mirror of https://github.com/MISP/misp-website
fix: [cleanup] cleanup of urls
parent
d8b3131f4e
commit
a1ace1a0b7
|
@ -348,7 +348,7 @@ disablePathToLower = "True"
|
|||
[[menu.main]]
|
||||
identifier = "contact"
|
||||
name = "Contact"
|
||||
url = "/contact/"
|
||||
url = "/support/"
|
||||
weight = 7
|
||||
|
||||
|
||||
|
|
|
@ -25,7 +25,7 @@ We'll monitor these aspects of a MISP server
|
|||
* MISP event, attribute, users and organisation statistics
|
||||
* HTTP response time
|
||||
|
||||
Interesting to know is that MISP already also has built-in features to monitor your system resources via [widgets and dashboards](https://www.misp-project.org/misp-training/a.a-widget-dev.pdf). There are widgets for monitoring system resources, MISP statistics and sightings.
|
||||
Interesting to know is that MISP already also has built-in features to monitor your system resources via [widgets and dashboards](/misp-training/a.a-widget-dev.pdf). There are widgets for monitoring system resources, MISP statistics and sightings.
|
||||
|
||||
## Cacti monitoring
|
||||
|
||||
|
|
|
@ -11,7 +11,7 @@ A new version of MISP ([2.4.102](https://github.com/MISP/MISP/tree/v2.4.102)) ha
|
|||
|
||||
### Anonymisation
|
||||
|
||||
Sharing and exchanging information encompasses a lot of different models, communities or practices, with the MISP project being involved in various discussions and projects centered around building sharing and information exchange communities. A complex topic comes up regularly, namely the anonymisation of the information exchanged. Sharing anonymised information often aims to simply share the existence of knowledge about information. We introduced a new attribute type in MISP called "anonymised", which can be combined with a newly introduced object called [anonymisation](https://www.misp-project.org/objects.html#_anonymisation).
|
||||
Sharing and exchanging information encompasses a lot of different models, communities or practices, with the MISP project being involved in various discussions and projects centered around building sharing and information exchange communities. A complex topic comes up regularly, namely the anonymisation of the information exchanged. Sharing anonymised information often aims to simply share the existence of knowledge about information. We introduced a new attribute type in MISP called "anonymised", which can be combined with a newly introduced object called [anonymisation](/objects.html#_anonymisation).
|
||||
|
||||

|
||||

|
||||
|
|
|
@ -36,9 +36,9 @@ A major project is ongoing to improve the UI accessibility in MISP, UI elements
|
|||
## Generic matrix-like galaxies are now supported
|
||||
|
||||
With the increased use of MITRE ATT&CK and the need of describing similar matrix-like models, generic matrix-like galaxies are now supported.
|
||||
You can create your own matrix with the associated custom kill chains. A first [new matrix-like galaxy](https://www.misp-project.org/galaxy.html#_election_guidelines) has been added to MISP called *Universal Development and Security Guidelines as Applicable to Election Technology* made by the [European Commission](https://www.ria.ee/sites/default/files/content-editors/kuberturve/cyber_security_of_election_technology.pdf) to model the attack model against election processes and technologies.
|
||||
You can create your own matrix with the associated custom kill chains. A first [new matrix-like galaxy](/galaxy.html#_election_guidelines) has been added to MISP called *Universal Development and Security Guidelines as Applicable to Election Technology* made by the [European Commission](https://www.ria.ee/sites/default/files/content-editors/kuberturve/cyber_security_of_election_technology.pdf) to model the attack model against election processes and technologies.
|
||||
|
||||
If you want to create your own matrix-like, [a slide deck called MISP Galaxy](https://www.misp-project.org/misp-training/3.2-misp-galaxy.pdf) part of the [MISP training materials](https://github.com/MISP/misp-training#misp-training-materials) explains the basics.
|
||||
If you want to create your own matrix-like, [a slide deck called MISP Galaxy](/misp-training/3.2-misp-galaxy.pdf) part of the [MISP training materials](https://github.com/MISP/misp-training#misp-training-materials) explains the basics.
|
||||
|
||||
# Security fix (CVE-2019-9482)
|
||||
|
||||
|
|
|
@ -10,7 +10,7 @@ A new version of MISP ([2.4.106](https://github.com/MISP/MISP/tree/v2.4.106)) ha
|
|||
# New features
|
||||
|
||||
- [API] Improved API to update warning-lists, object templates, the galaxy library, taxonomies and notice lists.
|
||||
- Searching the feed caches is now possible via both the UI and the API. This allows users to rapidly find out whether a provided value exists in any of the cached sources (feeds [feeds](https://www.misp-project.org/feeds/) and MISP servers alike).
|
||||
- Searching the feed caches is now possible via both the UI and the API. This allows users to rapidly find out whether a provided value exists in any of the cached sources (feeds [feeds](/feeds/) and MISP servers alike).
|
||||
- [CLI] Worker management is now exposed via the CLI. The listing, starting, restarting and killing of workers can now be simply accomplished via the CLI.
|
||||
- [CLI] reset/set a user's API key via the CLI. Overriding a password is now also possible without the need to force a password reset on login.
|
||||
- [Auth] [LinOTP](https://www.linotp.org/) authentication module added in MISP.
|
||||
|
|
|
@ -67,9 +67,9 @@ Many new [MISP modules](https://github.com/MISP/misp-modules) were added such as
|
|||
|
||||
# MISP galaxy, object templates and warning-lists updated
|
||||
|
||||
[MISP galaxy](https://www.misp-project.org/galaxy.html), [MISP object templates](https://www.misp-project.org/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
[MISP galaxy](/galaxy.html), [MISP object templates](/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
|
||||
New [default feeds](https://www.misp-project.org/feeds/) were added in MISP. Don't hesitate to contact us if you have any idea for new feeds.
|
||||
New [default feeds](/feeds/) were added in MISP. Don't hesitate to contact us if you have any idea for new feeds.
|
||||
|
||||
We would like to thank all the contributors, reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
|
|
|
@ -13,14 +13,14 @@ A new version of MISP ([2.4.109](https://github.com/MISP/MISP/tree/v2.4.109)) ha
|
|||
|
||||
## Encapsulate existing attributes into an object
|
||||
|
||||

|
||||

|
||||
|
||||
When an analyst inserts information into MISP, it's very common to start with a set of unstructured indicators/attributes. At a later stage, common structures emerge and combining attributes into objects start making more and more sense. However, the effort spent on the process of attribute creation would have to be repeated in prior versions via the object creation interface, something that resulted in analysts deciding to save time and effort and move on, leaving the unstructured data as is. To reduce the workload needed to bring structure to our prior work, we have now introduced a new feature, allowing users to easily select a set of attributes and automatically propose suitable object templates depending on the combination of types of the selected attributes. These in turn, can be gathered and processed into the desired object.
|
||||
|
||||
## Improved ATT&CK and ATT&CK-like matrix support
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
We received exhaustive feedback during the FIRST.org CTI conference in London and the [ATT&CK EU community](https://www.attack-community.org/) workshop at Eurocontrol concerning the ATT&CK integration in MISP. The matrix visualisation has been improved by sorting and reorganising the individual techniques based on their aggregate scores. These statistics can now easily be queried based on time-ranges, organisations, tags, along with all other restSearch enabled filters to generate ATT&CK like matrix views.
|
||||
|
||||
|
@ -42,17 +42,17 @@ An issue was discovered in MISP 2.4.108. Organisation admins could reset credent
|
|||
|
||||
- A long-standing bug has been fixed when adding tags or galaxies whilst using Firefox.
|
||||
- [permissions] Fixed the default sync/user/publisher permissions to include perm_tagger and perm_tag_editor(sync only).
|
||||
- And many other [fixes](https://www.misp-project.org/Changelog.txt).
|
||||
- And many other [fixes](/Changelog.txt).
|
||||
|
||||
# MISP galaxy, object templates and warning-lists updated
|
||||
|
||||
[MISP galaxy](https://www.misp-project.org/galaxy.html), [MISP object templates](https://www.misp-project.org/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
[MISP galaxy](/galaxy.html), [MISP object templates](/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
|
||||
New [default feeds](https://www.misp-project.org/feeds/) were added in MISP. Don't hesitate to contact us if you have any idea for new feeds.
|
||||
New [default feeds](/feeds/) were added in MISP. Don't hesitate to contact us if you have any idea for new feeds.
|
||||
|
||||
We would like to thank all the contributors, reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
# Warning: Next release 2.4.110
|
||||
|
||||
|
|
|
@ -15,12 +15,12 @@ A new version of MISP ([2.4.110](https://github.com/MISP/MISP/tree/v2.4.110)) ha
|
|||
|
||||
[misp-modules](https://github.com/MISP/misp-modules) now support MISP objects and relationships. The revamped system is still compatible with the old modules, whilst the new modules bolster up the complete MISP standard format. New modules such as [url-haus](https://github.com/MISP/misp-modules/blob/52dadd2df32b19241fdd978e50b717f1967e264b/misp_modules/modules/expansion/urlhaus.py), [joe sandbox query](https://github.com/MISP/misp-modules/blob/be61613da4f5dc8f082a7c1a9e1ec07fdb872560/misp_modules/modules/expansion/joesandbox_query.py) and many others support the new MISP standard format. This new feature allows module developers to create more advanced modules, generating MISP objects and associated relationships from any type of expansion, import or export modules in one click.
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
## Local tags introduced
|
||||
|
||||

|
||||

|
||||
|
||||
The long awaited feature "local tags" is now finally available. You can create tags locally if you are a member of the given MISP instance's host organisation, enabling "in-place" tagging for synchronisation and export filtering. MISP events are not modified while using the local tags and are in turn always stripped before being synchronised with other MISP instances and sharing communities. Local tags allow users to avoid violating the ownership model of MISP, but still be able to tag any event or attribute for further dissemination and data contextualisation. Local tagging works for tags, tag collections, galaxies and matrix-like galaxies such as ATT&CK.
|
||||
|
||||
|
@ -53,9 +53,9 @@ Thanks to the contribution from [Kortho](https://github.com/Kortho), the MISP us
|
|||
- Fixed socket extension parsing.
|
||||
- Fixed registry-key keys and values parsing for patterns.
|
||||
|
||||
[MISP galaxy](https://www.misp-project.org/galaxy.html), [MISP object templates](https://www.misp-project.org/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
[MISP galaxy](/galaxy.html), [MISP object templates](/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
|
||||
We would like to thank all the contributors, reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -20,8 +20,8 @@ At the MISP project, we are big supporters of new open standards, which can help
|
|||
|
||||
In 2.4.111, a new attribute type has thus been added, along with the following object templates already including the new attribute field:
|
||||
|
||||
- [Netflow](https://www.misp-project.org/objects.html#_netflow)
|
||||
- [Network connection](https://www.misp-project.org/objects.html#_network_connection)
|
||||
- [Netflow](/objects.html#_netflow)
|
||||
- [Network connection](/objects.html#_network_connection)
|
||||
|
||||
This feature allows to easily correlate network forensic flows from different tools or network equipment.
|
||||
|
||||
|
@ -34,9 +34,9 @@ This feature allows to easily correlate network forensic flows from different to
|
|||
- [stix2] Import of User Account objects is now supported.
|
||||
- Issues #4864, #4861, #4847 fixed
|
||||
|
||||
[MISP galaxy](https://www.misp-project.org/galaxy.html), [MISP object templates](https://www.misp-project.org/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
[MISP galaxy](/galaxy.html), [MISP object templates](/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version.
|
||||
|
||||
We would like to thank all the contributors, reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -31,7 +31,7 @@ A new version of MISP ([2.4.112](https://github.com/MISP/MISP/tree/v2.4.112)) ha
|
|||
|
||||
## Bugs fixed
|
||||
|
||||
Many bugs fixed based on the extensive PyMISP test cases in addition to manual reviews. All fixes are documented in the [changelog](https://www.misp-project.org/Changelog.txt).
|
||||
Many bugs fixed based on the extensive PyMISP test cases in addition to manual reviews. All fixes are documented in the [changelog](/Changelog.txt).
|
||||
|
||||
## CVE-2019-14286 fixed
|
||||
|
||||
|
@ -41,9 +41,9 @@ Many bugs fixed based on the extensive PyMISP test cases in addition to manual r
|
|||
|
||||
[misp-modules](https://misp.github.io/misp-modules/) have been improved with new modules especially with a new advanced CVE module which includes the ability to import CVEs along with their associated weaknesses and attack techniques (as you can see in the screenshot). The documentation has been also improved (thanks to all the contributors who helped us on the documentation).
|
||||
|
||||
[MISP galaxies](https://www.misp-project.org/galaxy.html), [MISP object templates](https://www.misp-project.org/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version. MISP galaxy has been updated to include the July edition of the MITRE ATT&CK model.
|
||||
[MISP galaxies](/galaxy.html), [MISP object templates](/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version. MISP galaxy has been updated to include the July edition of the MITRE ATT&CK model.
|
||||
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -88,9 +88,9 @@ A new version of MISP ([2.4.113](https://github.com/MISP/MISP/tree/v2.4.113)) wi
|
|||
|
||||
[misp-modules](https://misp.github.io/misp-modules/) have been improved with new modules especially an improved cuckoo import module (thanks to Pierre-Jean Grenier). The documentation has been also improved (thanks to all the contributors who helped us on the documentation).
|
||||
|
||||
[MISP galaxies](https://www.misp-project.org/galaxy.html), [MISP object templates](https://www.misp-project.org/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version. MISP galaxy now includes a target-location galaxy to improve classification.
|
||||
[MISP galaxies](/galaxy.html), [MISP object templates](/objects.html) and [MISP warning-lists](https://github.com/MISP/misp-warninglists/) have been updated to the latest version. MISP galaxy now includes a target-location galaxy to improve classification.
|
||||
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -34,7 +34,7 @@ Added a new diagnostic tool that allows administrators to keep track of the data
|
|||
|
||||
## Taxonomies improved with the addition of an Industrial control systems and operational technology (ICS/OT) Taxonomy
|
||||
|
||||
Industrial control systems and operational technologies (ICS/OT) are often the target of threats, intrusions and attacks. The [FIRST.org Cyber Threat Intelligence SIG](https://www.first.org/global/sigs/cti/) did a tremendous work of documenting these into a series of taxonomies. To support and actively test the use of the ICS/OT taxonomy, the [ics taxonomy](https://www.misp-project.org/taxonomies.html#_ics) is now part of the default MISP taxonomy library. We also encourage any ICS/OT operators to contribute back to the [ics taxonomy JSON file](https://github.com/MISP/misp-taxonomies/blob/master/ics/machinetag.json) in order to improve the taxonomy based on their experiences. By being a taxonomy in MISP, this allows all ICS/OT users to directly tag and contextualise information shared within MISP instances and communities to describe their domain specific incidents and reports along with the related industrial threat intelligence.
|
||||
Industrial control systems and operational technologies (ICS/OT) are often the target of threats, intrusions and attacks. The [FIRST.org Cyber Threat Intelligence SIG](https://www.first.org/global/sigs/cti/) did a tremendous work of documenting these into a series of taxonomies. To support and actively test the use of the ICS/OT taxonomy, the [ics taxonomy](/taxonomies.html#_ics) is now part of the default MISP taxonomy library. We also encourage any ICS/OT operators to contribute back to the [ics taxonomy JSON file](https://github.com/MISP/misp-taxonomies/blob/master/ics/machinetag.json) in order to improve the taxonomy based on their experiences. By being a taxonomy in MISP, this allows all ICS/OT users to directly tag and contextualise information shared within MISP instances and communities to describe their domain specific incidents and reports along with the related industrial threat intelligence.
|
||||
|
||||
## Fixes and improvements
|
||||
|
||||
|
@ -52,5 +52,5 @@ Special shout-outs to Jakub Onderka ([@JakubOnderka](https://github.com/JakubOnd
|
|||
|
||||
We would also like to make a special dedication to the funding support of [CIRCL](https://twitter.com/circl_lu) and [INEA](https://twitter.com/inea_eu) under the CEF Telecom [2016-LU-IA-0098 grant](https://ec.europa.eu/inea/sites/inea/files/cef_telecom_supported_actions_november_2018.pdf).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -25,7 +25,7 @@ A new version of MISP ([2.4.115](https://github.com/MISP/MISP/tree/v2.4.115)) wi
|
|||
|
||||
## Many fixes and error handling improvement
|
||||
|
||||
Thanks to Jakub Onderka for the tireless review of the code and all the fixes. For a complete overview, check the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
Thanks to Jakub Onderka for the tireless review of the code and all the fixes. For a complete overview, check the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
## CVE-2019-16202 - Vulnerability in MISP version <= 2.4.114
|
||||
|
||||
|
@ -76,9 +76,9 @@ Guenaëlle De Julis and Céline Massompierre from CERT-XLM of Excellium Services
|
|||
|
||||
We would like to reiterate the importance of continuous security testing and the reporting of findings. Without the diligent work of security professionals in our community, we would have an infinitely harder time of squashing potential vulnerabilities. Thanks again to everyone that has helped us make MISP more secure.
|
||||
|
||||
If you have found a vulnerability in MISP and would like to get in touch with us, please read our [vulnerability disclosure notice](https://www.misp-project.org/security/).
|
||||
If you have found a vulnerability in MISP and would like to get in touch with us, please read our [vulnerability disclosure notice](/security/).
|
||||
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -11,13 +11,13 @@ A new version of MISP ([2.4.116](https://github.com/MISP/MISP/tree/v2.4.116)) ha
|
|||
|
||||
## Major new feature - decaying indicators
|
||||
|
||||
After several years of gathering requirements, doing [research](https://arxiv.org/abs/1803.11052) and various implementation attempts, MISP 2.4.116 finally includes [a new extensive feature for Decaying Indicators](https://www.misp-project.org/2019/09/12/Decaying-Of-Indicators.html) using an advanced model to expire indicators based on custom and shareable models.
|
||||
After several years of gathering requirements, doing [research](https://arxiv.org/abs/1803.11052) and various implementation attempts, MISP 2.4.116 finally includes [a new extensive feature for Decaying Indicators](/2019/09/12/Decaying-Of-Indicators.html) using an advanced model to expire indicators based on custom and shareable models.
|
||||
|
||||
The feature allows MISP users to have a simple yet customisable system to automatically (or in some cases semi-manually) mark an Indicator Of Compromise (or more generally, an Attribute) as expired. The expiration system allows for the overlaying of computed scores on all attributes in real-time, based on the configured mappings via a decay model. The feature has been designed not to change the attributes per se, but rather to extend the meta information available about the attributes. As with everything in MISP, this new feature is accessible via both the user-interface and also via the API, in order to allow for the filtering of attributes based on a decay model.
|
||||
|
||||
<img src="/img/blog/decaying/dm-event.png" alt="Decay Model index" width="700"/>
|
||||
|
||||
The feature is exhaustive and we highly recommend to read the [blog post and watch the video showing all aspects of the new feature](https://www.misp-project.org/2019/09/12/Decaying-Of-Indicators.html) or [the slides from the MISP training](https://www.misp-project.org/misp-training/a.5-decaying-indicators.pdf). As usual, MISP comes with a set of default decay models which can be extended locally or contributed back to the community at large.
|
||||
The feature is exhaustive and we highly recommend to read the [blog post and watch the video showing all aspects of the new feature](/2019/09/12/Decaying-Of-Indicators.html) or [the slides from the MISP training](/misp-training/a.5-decaying-indicators.pdf). As usual, MISP comes with a set of default decay models which can be extended locally or contributed back to the community at large.
|
||||
|
||||
## ATT&CK sighting
|
||||
|
||||
|
@ -31,5 +31,5 @@ When having a lot of MISP server to sync with, you might want to prioritise the
|
|||
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -51,5 +51,5 @@ Other improvements include a large list of general bug fixes, affecting UI and A
|
|||
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. Special thanks to Jakub Onderka for the continuous stream of excellent improvements, Andreas Rammhold for making the AppController much more sane, the participants of the cyber-exchange programme for helping us improve MISP in all sorts of different ways.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -11,10 +11,10 @@ A new version of MISP ([2.4.118](https://github.com/MISP/MISP/tree/v2.4.118)) ha
|
|||
|
||||
# Exclusive taxonomies
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
Some time ago, we've introduced the "exclusive" field in the MISP taxonomy format, in order to define rules of exclusivity within a given taxonomy predicate. As of this release, the MISP user-interface shows and enforces inconsistencies of exclusivity between tags assigned at the event and the attribute levels.
|
||||
|
||||
|
@ -67,7 +67,7 @@ The database schema model update has been improved in MISP and you can see the c
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. Special thanks to Jakub Onderka for the continuous stream of excellent improvements, Sebastien Tricaud for the joint effort in the SightingDB support, [standard](https://raw.githubusercontent.com/MISP/misp-rfc/master/sightingdb-format/raw.md.txt) and [first implementation](https://github.com/stricaud/sightingdb).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. Special thanks to Jakub Onderka for the continuous stream of excellent improvements, Sebastien Tricaud for the joint effort in the SightingDB support, [standard](https://raw.githubusercontent.com/MISP/misp-rfc/master/sightingdb-format/raw.md.txt) and [first implementation](https://github.com/stricaud/sightingdb).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -55,7 +55,7 @@ MISP modules have been improved and many new modules were added in [expansion](h
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -39,7 +39,7 @@ MISP modules have been improved and many new modules were added in the following
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -46,12 +46,12 @@ A massive list of improvements to the usability of MISP, with a special thank yo
|
|||
|
||||
# MISP Objects templates
|
||||
|
||||
We received a significant number of [new object templates](https://www.misp-project.org/objects.html) to describe specific additional use cases including disinformation, media and also improved HTTP representation.
|
||||
We received a significant number of [new object templates](/objects.html) to describe specific additional use cases including disinformation, media and also improved HTTP representation.
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -30,8 +30,8 @@ A bug fix solves an issue where attribute edits could purge correlations. The bu
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -30,7 +30,7 @@ The new Dashboard is accessible directly in MISP and fully customisable by users
|
|||
|
||||
- The system relies on bundled and custom widgets
|
||||
- widgets work similarly to other modular parts of MISP, design your own, drop it in the MISP directory to get started
|
||||
- For instructions on how to develop a basic widget visit [The training slide repository](https://www.misp-project.org/misp-training/a.a-widget-dev.pdf)
|
||||
- For instructions on how to develop a basic widget visit [The training slide repository](/misp-training/a.a-widget-dev.pdf)
|
||||
- Under the hood it uses the user settings system, allowing for custom configurations per user
|
||||
- Dashboard templates can be saved and shared, both via MISP and via JSON configuration files
|
||||
- Widgets come with a host of support functionalities (ACL, caching, auto-reloading, configuration systems)
|
||||
|
@ -49,8 +49,8 @@ Due to a recently introduced bug, we had cases of correlations disappearing afte
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -30,7 +30,7 @@ Finally, the widget styling is largely configurable. In addition to the `time_fo
|
|||
|
||||
# New community CogSec Collab disinformation
|
||||
|
||||
MISP includes the possibility to advertise your MISP information sharing community, don't hesitate to propose your community to gain some visibility. We added "[The Cognitive Security Collaborative operates as a sharing community dedicated to information operations](https://www.misp-project.org/2020/03/26/cogsec-collab-misp-community.html)".
|
||||
MISP includes the possibility to advertise your MISP information sharing community, don't hesitate to propose your community to gain some visibility. We added "[The Cognitive Security Collaborative operates as a sharing community dedicated to information operations](/2020/03/26/cogsec-collab-misp-community.html)".
|
||||
|
||||
# COVID-19 MISP
|
||||
|
||||
|
@ -39,12 +39,12 @@ COVID-19 MISP is a MISP instance retrofitted for a COVID-19 information sharing
|
|||
- Medical information
|
||||
- Cyber threats related to / abusing COVID-19
|
||||
|
||||
The information sharing community has a low barrier of entry, everyone can contribute and use the data. By default, the information is classified as TLP:WHITE for broader distribution and usefulness. [For more information and joining the COVID-19 MISP community](https://www.misp-project.org/covid-19-misp/)
|
||||
The information sharing community has a low barrier of entry, everyone can contribute and use the data. By default, the information is classified as TLP:WHITE for broader distribution and usefulness. [For more information and joining the COVID-19 MISP community](/covid-19-misp/)
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -44,12 +44,12 @@ To add a second layer of security, OTP has been made available thanks to the con
|
|||
- [database] New MySQL data source added for debugging.
|
||||
- MySQLObserver datasource added - prepends all queries with the requested controller/action and user ID for better debugging
|
||||
|
||||
May improvements were done in this MISP release, for a complete overview, you can have a look at the [complete changelog](https://www.misp-project.org/Changelog.txt).
|
||||
May improvements were done in this MISP release, for a complete overview, you can have a look at the [complete changelog](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -29,8 +29,8 @@ A long list of improvements, fixes and new functionalities have been added, make
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -43,12 +43,12 @@ Don't hesitate to contribute your own widgets and take a look at the existing on
|
|||
- Make correlation saving faster (move more work to database, do not fetch not necessary fields)
|
||||
- Fix some small bugs
|
||||
|
||||
Many other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
Many other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -11,7 +11,7 @@ A new version of MISP ([2.4.128](https://github.com/MISP/MISP/tree/v2.4.128)) ha
|
|||
|
||||
# STIX 2 and 1 major refactoring and improvements
|
||||
|
||||
A major refactoring of the STIX (version 1 and version 2) import/export has been performed by Christian Studer. We invite you to read the [Changelog](https://www.misp-project.org/Changelog.txt) for the complete set of changes and improvements. The most significant change is the import of threat-actors, tools and alike. As of this version on, the import process automatically maps the data-points to existing galaxies. As an example, if a synonym of a threat-actor is found in the original STIX file, the import process will attach the existing threat-actor from the MISP galaxy library. It also works with tags.
|
||||
A major refactoring of the STIX (version 1 and version 2) import/export has been performed by Christian Studer. We invite you to read the [Changelog](/Changelog.txt) for the complete set of changes and improvements. The most significant change is the import of threat-actors, tools and alike. As of this version on, the import process automatically maps the data-points to existing galaxies. As an example, if a synonym of a threat-actor is found in the original STIX file, the import process will attach the existing threat-actor from the MISP galaxy library. It also works with tags.
|
||||
|
||||
# Security fix
|
||||
|
||||
|
@ -22,12 +22,12 @@ A major refactoring of the STIX (version 1 and version 2) import/export has been
|
|||
- [correlations] Enable CIDR correlations for ip-src|port and ip-dst|port types
|
||||
- [widget] Authentication failure widget added to provide a dashboard from [D4 project](https://www.d4-project.org/).
|
||||
|
||||
Many other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
Many other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -24,12 +24,12 @@ A new version of MISP ([2.4.129](https://github.com/MISP/MISP/tree/v2.4.129)) ha
|
|||
|
||||
# Many bugs fixed and small improvements
|
||||
|
||||
Many other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
Many other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -63,12 +63,12 @@ A new version of MISP ([2.4.130](https://github.com/MISP/MISP/tree/v2.4.130)) ha
|
|||
|
||||
# Many bugs fixed and small improvements
|
||||
|
||||
Many other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
Many other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -29,12 +29,12 @@ A new version of MISP ([2.4.131](https://github.com/MISP/MISP/tree/v2.4.131)) ha
|
|||
|
||||
# Many bugs fixed and small improvements
|
||||
|
||||
A host of other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
A host of other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -7,7 +7,7 @@ banner: /img/blog/d4_sshd_widget.png
|
|||
|
||||
# MISP 2.4.132 released
|
||||
|
||||
A new version of MISP ([2.4.132](https://github.com/MISP/MISP/tree/v2.4.132)) has been released with several bugs fixed including an important [security](https://www.misp-project.org/security/) fix [CVE-2020-25766](https://cve.circl.lu/cve/CVE-2020-25766).
|
||||
A new version of MISP ([2.4.132](https://github.com/MISP/MISP/tree/v2.4.132)) has been released with several bugs fixed including an important [security](/security/) fix [CVE-2020-25766](https://cve.circl.lu/cve/CVE-2020-25766).
|
||||
|
||||
# Bugs fixed and updates
|
||||
|
||||
|
@ -26,12 +26,12 @@ Version 2.4.133 will include a new diagnostic tool that highlights deletions fro
|
|||
|
||||
# Many bugs fixed and small improvements
|
||||
|
||||
A host of other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
A host of other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html).
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html).
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
||||
|
|
|
@ -18,8 +18,8 @@ However, in the current threat intelligence scene, information is often explaine
|
|||
In MISP 2.4.133, the report feature has been introduced including a complete Markdown editor to edit one or more report(s) attach to an event. The report feature including
|
||||
a complete editor to allow an interactive method to add structured information from the MISP event including attributes, objects, galaxies or tags into the report.
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
The report editor provides features such as:
|
||||
|
||||
|
@ -30,13 +30,13 @@ The report editor provides features such as:
|
|||
- Fullscreen and resizable interface
|
||||
- Time since last edit & quick save
|
||||
|
||||

|
||||

|
||||
|
||||
Event reports have all the standard properties regarding information sharing available MISP such as distribution level, sharing communities. A report can be shared to specific groups while structured information can be shared to a wider audience as an example.
|
||||
|
||||
*Event reports* also offer a wide range of new possibilities that were not doable efficiently before. For example, Counter analysis on cases can be explained, resolution steps and recommendations can be supplied, and complete articles can be included inside an *event*.
|
||||
|
||||
For more details, check out our blog post: [Event Report: A convenient mechanism to edit, visualize and share reports](https://www.misp-project.org/2020/10/08/Event-Reports.html).
|
||||
For more details, check out our blog post: [Event Report: A convenient mechanism to edit, visualize and share reports](/2020/10/08/Event-Reports.html).
|
||||
|
||||
# New features
|
||||
|
||||
|
@ -69,12 +69,12 @@ For more details, check out our blog post: [Event Report: A convenient mechanism
|
|||
|
||||
# Many bugs fixed and small improvements
|
||||
|
||||
A host of other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
A host of other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -7,7 +7,7 @@ banner: /img/blog/event-reports/report-modal.png
|
|||
|
||||
# MISP 2.4.134 released
|
||||
|
||||
In the previous version of MISP, the new [Event Report functionality](https://www.misp-project.org/2020/10/08/Event-Reports.html) has been introduced to edit, visualise and share reports in Markdown format, which includes the ability to reference elements from within a MISP event.
|
||||
In the previous version of MISP, the new [Event Report functionality](/2020/10/08/Event-Reports.html) has been introduced to edit, visualise and share reports in Markdown format, which includes the ability to reference elements from within a MISP event.
|
||||
|
||||
In the current version, the Event Report has been extended to support the automatic discovery of attributes, galaxies and tags from any website captured.
|
||||
|
||||
|
@ -47,12 +47,12 @@ A security vulnerability [CVE-2020-28043](https://cve.circl.lu/cve/CVE-2020-2804
|
|||
- Tag index has been improved with a simple view excludes eventtags / attributetags / sightings
|
||||
- Many UI improvements (thanks to Jakub Onderka for his continuous effort and attention to details)
|
||||
|
||||
A host of other improvements are documented in the [complete changelog is available](https://www.misp-project.org/Changelog.txt).
|
||||
A host of other improvements are documented in the [complete changelog is available](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -10,12 +10,12 @@ banner: /img/blog/galaxy2.0/4.jpeg
|
|||
Don’t let the minor version number change fool you, this release is a game changer for MISP and information sharing in general. Galaxy 2.0 brings about the ability to customise Galaxy clusters (threat-actors, @MITREattack or any knowledge base element) as well as to extend and share it within your community. This release also includes many new improvements such as a new authkey system to better handle your API keys in MISP.
|
||||
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
The galaxy 2.0 feature is large and provide many new features. For a complete overview, the [following slide deck](https://www.misp-project.org/misp-training/a.10-galaxy-2.0.pdf) provides a good introduction to galaxy 2.0.
|
||||
The galaxy 2.0 feature is large and provide many new features. For a complete overview, the [following slide deck](/misp-training/a.10-galaxy-2.0.pdf) provides a good introduction to galaxy 2.0.
|
||||
|
||||
# New Advanced API authkeys
|
||||
|
||||
|
@ -31,12 +31,12 @@ MISP (and MISP standard format) now includes the support for [JARM](https://gith
|
|||
- For objects from external STIX content that should be mapped as galaxies (such as malware, threat actor, and so on), we do not only test the perfect match with one of the galaxy names in the mapping dictionary, we also test now if the galaxy name is contained in any of the known galaxy names of the dictionary
|
||||
|
||||
|
||||
Additionally, a host of other improvements are documented in the [complete changelog](https://www.misp-project.org/Changelog.txt).
|
||||
Additionally, a host of other improvements are documented in the [complete changelog](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -45,8 +45,8 @@ This allows us to still include hotfixes and urgent bugfixes on 2.4, without mud
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -11,7 +11,7 @@ We have released 2.4.137, a security and bug fix release including a collection
|
|||
|
||||
Building tools for the security community sure has its perks - over the past week we have received two independent security test results of two separate organisations, revealing several vulnerabilities. The update to this version is therefore highly recommended.
|
||||
|
||||
A little note on vulnerability - we [always welcome organisations helping us secure MISP](https://www.misp-project.org/security/) and our tooling in general and would hereby like to thank everyone taking part in the process!
|
||||
A little note on vulnerability - we [always welcome organisations helping us secure MISP](/security/) and our tooling in general and would hereby like to thank everyone taking part in the process!
|
||||
|
||||
# Several vulnerabilities resolved
|
||||
|
||||
|
@ -31,8 +31,8 @@ Along with many other fixes. A special thank you to @JakubOnderka for providing
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -9,7 +9,7 @@ banner: /img/blog/rsit-3.png
|
|||
|
||||
We have released 2.4.138, the latest release for MISP along with an update of the JSON libraries.
|
||||
|
||||
Besides that, several usability and performance issues have been resolved along with a host of small improvements, additional API improvements, etc. Make sure that you read the [detailed changelog](https://www.misp-project.org/Changelog.txt) to see all the improvements. Improvements include the use of the threat level for the alert filtering, many bugs fixed in the event graph and many others.
|
||||
Besides that, several usability and performance issues have been resolved along with a host of small improvements, additional API improvements, etc. Make sure that you read the [detailed changelog](/Changelog.txt) to see all the improvements. Improvements include the use of the threat level for the alert filtering, many bugs fixed in the event graph and many others.
|
||||
|
||||
# Nested Galaxy Element generator
|
||||
|
||||
|
@ -20,17 +20,17 @@ We have a new tool that allows you to take nested JSON documents and convert it
|
|||
|
||||
# RSIT galaxy added with MITRE ATT&CK
|
||||
|
||||
[Reference Security Incident Taxonomy Working Group](https://github.com/enisaeu/Reference-Security-Incident-Taxonomy-Task-Force), is a joint initiative for CSIRTs to produce a reference taxonomy for the CSIRT community. A new version of RIST has been integrated into MISP along with a complete set of relationships with MITRE ATT&CK, thanks to the [galaxy 2.0 feature](https://www.misp-project.org/2020/12/16/MISP.2.4.135.released.html) in MISP. Thanks to [Koen Van Impe](https://www.cudeso.be/) for this new updated galaxy.
|
||||
[Reference Security Incident Taxonomy Working Group](https://github.com/enisaeu/Reference-Security-Incident-Taxonomy-Task-Force), is a joint initiative for CSIRTs to produce a reference taxonomy for the CSIRT community. A new version of RIST has been integrated into MISP along with a complete set of relationships with MITRE ATT&CK, thanks to the [galaxy 2.0 feature](/2020/12/16/MISP.2.4.135.released.html) in MISP. Thanks to [Koen Van Impe](https://www.cudeso.be/) for this new updated galaxy.
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -13,7 +13,7 @@ Besides that, several usability and performance issues have been resolved along
|
|||
|
||||
# MISP modules are now Event Report aware!
|
||||
|
||||
The Event Reports are the hot new feature of the past few weeks and we are working on ensuring that analyst reports are becoming the standard companions of the classic event format. For anyone that hasn't played with them before, have a look at the [blog post](https://www.misp-project.org/2020/10/08/Event-Reports.html) describing how you can create rich, interlinked reports to accompany your events.
|
||||
The Event Reports are the hot new feature of the past few weeks and we are working on ensuring that analyst reports are becoming the standard companions of the classic event format. For anyone that hasn't played with them before, have a look at the [blog post](/2020/10/08/Event-Reports.html) describing how you can create rich, interlinked reports to accompany your events.
|
||||
|
||||
The main update to the Event Report system is its inclusion in the module system as of this version, so if you are building integrations with MISP or simply want to build a convenient way to incorporate reports from your favourite information sources, this feature will make your life much easier.
|
||||
|
||||
|
@ -35,8 +35,8 @@ This widget also brings a flexible reusable UI layer with itself that widget dev
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -33,7 +33,7 @@ Additionally, a new set of CLI tools is being built for developers, to ease our
|
|||
|
||||
# New types added in MISP
|
||||
|
||||
New full-name, dkim and dkim-signature attribute types were added to MISP. Associated to [DKIM objects](https://www.misp-project.org/objects.html#_dkim) were included to support tools such as Farsight Security dnsdb to add DKIM information in your investigations.
|
||||
New full-name, dkim and dkim-signature attribute types were added to MISP. Associated to [DKIM objects](/objects.html#_dkim) were included to support tools such as Farsight Security dnsdb to add DKIM information in your investigations.
|
||||
|
||||
# Security Vulnerability
|
||||
|
||||
|
@ -41,8 +41,8 @@ An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -24,7 +24,7 @@ MISP 2.4.141 released including many improvements from email notification, UI, A
|
|||
- [UI] Simplify keyboard-shortcuts.js.
|
||||
- [UI] Use Page Visibility API.
|
||||
|
||||
and many more updates check the [changelog for details](https://www.misp-project.org/Changelog.txt).
|
||||
and many more updates check the [changelog for details](/Changelog.txt).
|
||||
|
||||
# Email notification
|
||||
|
||||
|
@ -45,8 +45,8 @@ Many improvement in the RHEL7, 7.9 and CentOS8Stream. We thank all the users rep
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -23,7 +23,7 @@ Once added, you can execute the cleaning of the existing correlations, to retroa
|
|||
|
||||
You can also comment your reason for removing an entry. In the future we plan on publishing community maintained default exclusion lists.
|
||||
|
||||

|
||||

|
||||
|
||||
### Top correlations
|
||||
|
||||
|
@ -33,7 +33,7 @@ Just hit the delete button on a correlation and it will add a rule to your corre
|
|||
|
||||
# Server sync rule management rework
|
||||
|
||||

|
||||

|
||||
|
||||
One of the more painful aspects of managing servers has been the historically bad UI used to manage filter rules. This has now been completely revamped, both with a new look but familiar look and feel as well as some clever new tools to make it more usable.
|
||||
|
||||
|
@ -43,18 +43,18 @@ For example, when creating pull filters, your instance will now attempt to conta
|
|||
|
||||
Thanks to Jeroen Pinoy, we have some new dashboard widgets meant to give you better oversight over how your instance is being used, showing some usage statistics as well as tools to monitor the growth of the user base of the community.
|
||||
|
||||

|
||||

|
||||
|
||||
# A bunch of other fixes including security fixes
|
||||
|
||||
We have also a [security](https://www.misp-project.org/security/) issue (CVE-2021-31780) causing a potential misalignment of sharing groups on synced attributes, so we highly encourage everyone to update their MISP instance.
|
||||
We have also a [security](/security/) issue (CVE-2021-31780) causing a potential misalignment of sharing groups on synced attributes, so we highly encourage everyone to update their MISP instance.
|
||||
|
||||
Besides that we have introduced a long list of quality of life improvements as well as [many fixes](https://www.misp-project.org/Changelog.txt).
|
||||
Besides that we have introduced a long list of quality of life improvements as well as [many fixes](/Changelog.txt).
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
. The MISP galaxy includes a major update in the Ransomware galaxy which now includes more than 1600 documented ransomware.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -38,8 +38,8 @@ Two new MISP modules were introduced:
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -11,7 +11,7 @@ MISP 2.4.144 released including a massive update to the documentation along with
|
|||
|
||||
# OpenAPI integration
|
||||
|
||||
We have a new core team member at MISP Project, Luciano (@righel), who kicked off his tenure with an impressive mapping of all the most important endpoints of MISP to OpenAPI. As of this release, the API documentation is directly available in MISP, along with example payloads and responses. You can also find [this information directly on the misp-project website](https://www.misp-project.org/documentation/openapi.html). To all integrators and developers wrangling with the API, we highly recommend you take a look at the API menu in MISP and we wish you happy and headache-free hacking!
|
||||
We have a new core team member at MISP Project, Luciano (@righel), who kicked off his tenure with an impressive mapping of all the most important endpoints of MISP to OpenAPI. As of this release, the API documentation is directly available in MISP, along with example payloads and responses. You can also find [this information directly on the misp-project website](/documentation/openapi.html). To all integrators and developers wrangling with the API, we highly recommend you take a look at the API menu in MISP and we wish you happy and headache-free hacking!
|
||||
|
||||
# New diagrams and descriptions
|
||||
|
||||
|
@ -22,13 +22,13 @@ Thanks to the thorough investigations of @mokaddem, we now have the entire synch
|
|||
|
||||
# CyCAT integration v1
|
||||
|
||||

|
||||

|
||||
|
||||
CyCAT is a new initiative built by a group of individuals with the aim of cataloguing all the techniques and libraries around cyber-security, mostly with the selfish desire to make their own confusing lives easier (along with all those that are in a similar situation). As of this release, you'll be able to enable a first version of the CyCAT integration in MISP directly, allowing you to directly see relations to your galaxy clusters via CyCAT's own relationship system, giving you an extra layer of background information with the clusters already in use.
|
||||
|
||||
If you are interested in CyCAT and what it can do for you, head over to the [CyCAT website](https://cycat.org/).
|
||||
|
||||
To enable the CyCAT integration, got to the Plugin settings  and enable the feature.
|
||||
To enable the CyCAT integration, got to the Plugin settings  and enable the feature.
|
||||
|
||||
# Improvements
|
||||
|
||||
|
@ -37,8 +37,8 @@ To enable the CyCAT integration, got to the Plugin settings , reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -50,8 +50,8 @@ Thanks to the reporters including Nicolas Vidal from TEHTRIS.
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -27,8 +27,8 @@ This release also includes refactoring of various forms to support future major
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -18,8 +18,8 @@ MISP 2.4.148 released including many bugs fixed along with security fixes. This
|
|||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -26,7 +26,7 @@ MISP 2.4.149 released including many bugs fixed along with some new and improved
|
|||
|
||||
- Allow the fetching of sharing group data from Cerebrate instances, our new open source tool in development aiming to solve a host of issues revolving around community management and orchestration. Our first official release of the tool is scheduled for the MISP summit coming up this month
|
||||
- To follow the cerebrate project, head over to its [github page](https://github.com/cerebrate-project/cerebrate)
|
||||
- For the MISP summit to be held on the 21st of October, don't forget to watch the [misp-summit](https://www.misp-project.org/misp-summit). You can still apply for the [Call-for-Presentation](https://cfp.hack.lu/misp-2021/cfp).
|
||||
- For the MISP summit to be held on the 21st of October, don't forget to watch the [misp-summit](/misp-summit). You can still apply for the [Call-for-Presentation](https://cfp.hack.lu/misp-2021/cfp).
|
||||
|
||||
# mail2misp release 1.0
|
||||
|
||||
|
@ -35,11 +35,11 @@ First [official release 1.0 of mail2misp](https://github.com/MISP/mail_to_misp/r
|
|||
# Various improvements
|
||||
|
||||
- A long list of improvements, massive thanks to @JakubOnderka for the continuous stream of improvements and quality of life changes
|
||||
- Thanks to the work of @righel, our [OpenAPI documentation](https://www.misp-project.org/documentation/openapi.html) is becoming more and more complete, now covering a long list of the more exotic endpoints and options
|
||||
- Thanks to the work of @righel, our [OpenAPI documentation](/documentation/openapi.html) is becoming more and more complete, now covering a long list of the more exotic endpoints and options
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
|
|
@ -13,8 +13,8 @@ MISP 2.4.150 released, including a new CA bundle to combat the issues with the L
|
|||
|
||||
As described in their [blog post](https://letsencrypt.org/docs/dst-root-ca-x3-expiration-september-2021/#:~:text=On%20September%2030%202021%2C%20there,accept%20your%20Let's%20Encrypt%20certificate), Letsencrpyt had to retire an old Root CA, meaning that that SSL connections when synchronising MISP with other instances would fail if the remote side used letsencrypt. This update includes a new CA bundle that should help you avoid any issues with this.# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -38,7 +38,7 @@ MISP 2.4.151 released including a host of bug fixes and a bunch of new features
|
|||
# Various improvements
|
||||
|
||||
- The previous version introduced a new STIX library as a replacement for the old one. This change did end up causing some update issues for some installations, the built in updater is now aware of this change and should allow you to easily update via the UI/API updater, with the new STIX library working as intended
|
||||
- A long list of improvements, thanks to all contributors! For a detailed list of changes, head over to the [changelog](https://www.misp-project.org/Changelog.txt)
|
||||
- A long list of improvements, thanks to all contributors! For a detailed list of changes, head over to the [changelog](/Changelog.txt)
|
||||
|
||||
# MISP Modules
|
||||
|
||||
|
@ -46,21 +46,21 @@ MISP 2.4.151 released including a host of bug fixes and a bunch of new features
|
|||
- Updated [Recorded Future](https://misp.github.io/misp-modules/expansion/#recordedfuture) expansion module included links and related data.
|
||||
- New [CIRCL hashlookup expansion](https://circl.lu/services/hashlookup/) module added.
|
||||
|
||||
The [MISP modules changelog is available](https://www.misp-project.org/Changelog-misp-modules.txt).
|
||||
The [MISP modules changelog is available](/Changelog-misp-modules.txt).
|
||||
|
||||
# MISP Taxonomies
|
||||
|
||||
- Updated taxonomies for [Interactive Cyber Training setup and environment](https://www.misp-project.org/taxonomies.html#_interactive_cyber_training_audience).
|
||||
- Updated [fr-classification](https://www.misp-project.org/taxonomies.html#_fr_classif) to match IGI1300.
|
||||
- Updated taxonomies for [Interactive Cyber Training setup and environment](/taxonomies.html#_interactive_cyber_training_audience).
|
||||
- Updated [fr-classification](/taxonomies.html#_fr_classif) to match IGI1300.
|
||||
|
||||
[MISP Taxonomies changelog](https://www.misp-project.org/Changelog-misp-taxonomies.txt) is available.
|
||||
[MISP Taxonomies changelog](/Changelog-misp-taxonomies.txt) is available.
|
||||
|
||||
# MISP Galaxy
|
||||
|
||||
- Updated to MITRE ATT&CK version 10.
|
||||
- Multiple updates in malpedia, threat actor galaxy and Office 365 techniques.
|
||||
|
||||
[MISP Galaxy changelog](https://www.misp-project.org/Changelog-misp-galaxy.txt)
|
||||
[MISP Galaxy changelog](/Changelog-misp-galaxy.txt)
|
||||
|
||||
# MISP Objects
|
||||
|
||||
|
@ -72,12 +72,12 @@ The [MISP modules changelog is available](https://www.misp-project.org/Changelog
|
|||
- New hashlookup object added.
|
||||
- New edr-report object added.
|
||||
|
||||
[MISP objects changelog](https://www.misp-project.org/Changelog-misp-objects.txt)
|
||||
[MISP objects changelog](/Changelog-misp-objects.txt)
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements.
|
||||
|
||||
|
|
|
@ -24,22 +24,22 @@ Many internal improvements and bugs fixed.
|
|||
- New [Qintel sentry module](https://misp.github.io/misp-modules/expansion/#qintel_qsentry) added.
|
||||
- [CIRCL hashlookup expansion](https://circl.lu/services/hashlookup/) SHA-256 support added.
|
||||
|
||||
The [MISP modules changelog is available](https://www.misp-project.org/Changelog-misp-modules.txt).
|
||||
The [MISP modules changelog is available](/Changelog-misp-modules.txt).
|
||||
|
||||
# MISP Taxonomies
|
||||
|
||||
- New [political spectrum taxonomy](https://www.misp-project.org/taxonomies.html#_political_spectrum) added.
|
||||
- New [political spectrum taxonomy](/taxonomies.html#_political_spectrum) added.
|
||||
- Improvement in exercise taxonomy.
|
||||
- New [deception taxonomy](https://www.misp-project.org/taxonomies.html#_deception) added.
|
||||
- New [deception taxonomy](/taxonomies.html#_deception) added.
|
||||
|
||||
[MISP Taxonomies changelog](https://www.misp-project.org/Changelog-misp-taxonomies.txt) is available.
|
||||
[MISP Taxonomies changelog](/Changelog-misp-taxonomies.txt) is available.
|
||||
|
||||
# MISP Galaxy
|
||||
|
||||
- New matrix [CONCORDIA Mobile Modelling Framework - Attack Pattern](https://www.misp-project.org/galaxy.html#_concordia_mobile_modelling_framework_attack_pattern) added (thanks to [Concordia H2020 project](https://www.concordia-h2020.eu/)).
|
||||
- New matrix [CONCORDIA Mobile Modelling Framework - Attack Pattern](/galaxy.html#_concordia_mobile_modelling_framework_attack_pattern) added (thanks to [Concordia H2020 project](https://www.concordia-h2020.eu/)).
|
||||
- Many update in threat actor, RAT and tools galaxy.
|
||||
|
||||
[MISP Galaxy changelog](https://www.misp-project.org/Changelog-misp-galaxy.txt)
|
||||
[MISP Galaxy changelog](/Changelog-misp-galaxy.txt)
|
||||
|
||||
# MISP Objects
|
||||
|
||||
|
@ -48,12 +48,12 @@ The [MISP modules changelog is available](https://www.misp-project.org/Changelog
|
|||
- Many improvements in user, person, postal-address, email object.
|
||||
- New relationships added such as `found-in`, `works-with`, `drives`.
|
||||
|
||||
[MISP objects changelog](https://www.misp-project.org/Changelog-misp-objects.txt)
|
||||
[MISP objects changelog](/Changelog-misp-objects.txt)
|
||||
|
||||
# Acknowledgement
|
||||
|
||||
We would like to thank all the [contributors](https://www.misp-project.org/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](https://www.misp-project.org/objects.html), [misp-taxonomies](https://www.misp-project.org/taxonomies.html) and [misp-galaxy](https://www.misp-project.org/galaxy.html)
|
||||
We would like to thank all the [contributors](/contributors), reporters and users who have helped us in the past months to improve MISP and information sharing at large. This release includes multiple updates in [misp-objects](/objects.html), [misp-taxonomies](/taxonomies.html) and [misp-galaxy](/galaxy.html)
|
||||
.
|
||||
|
||||
As always, a detailed and [complete changelog is available](https://www.misp-project.org/Changelog.txt) with all the fixes, changes and improvements in MISP core.
|
||||
As always, a detailed and [complete changelog is available](/Changelog.txt) with all the fixes, changes and improvements in MISP core.
|
||||
|
||||
|
|
|
@ -11,7 +11,7 @@ A new version of MISP [2.4.80](https://github.com/MISP/MISP/tree/v2.4.80) has be
|
|||
|
||||
MISP now includes support for MISP objects. This allows MISP to support complex/combined objects in a flexible way along with their [relationships](http://www.misp-project.org/objects.html#_relationships) towards other objects or even attributes.
|
||||
|
||||
MISP objects already available by default are documented in [HTML](https://www.misp-project.org/objects.html) or [PDF](https://www.misp-project.org/objects.pdf).
|
||||
MISP objects already available by default are documented in [HTML](/objects.html) or [PDF](/objects.pdf).
|
||||
|
||||
The object model allows MISP users to add objects in addition to standard attributes to an event. Objects are composed of one or more attributes which are defined by the object templates.
|
||||
The [object templates](https://github.com/MISP/misp-objects/tree/master/objects) are public and can be easily contributed to by everyone, allowing analysts, users and security professionals to build their own representation of various objects and share them back to their communities.
|
||||
|
|
|
@ -44,7 +44,7 @@ The following columns will be returned (all columns related to objects will be p
|
|||
|
||||
includeContext option includes the tags for the event for each line.
|
||||
|
||||
The STIX 2.0 export has been improved to include custom objects, Person object included in Identity SDO, tool SDO now includes [exploit-kit from MISP galaxy](/galaxy.html#_exploit_kit) and all the [galaxy which can be mapped](https://www.misp-project.org/galaxy.html), course-of-action SDO added. Export code has been improved to cope with the utter complex mess of STIX patterning standard.
|
||||
The STIX 2.0 export has been improved to include custom objects, Person object included in Identity SDO, tool SDO now includes [exploit-kit from MISP galaxy](/galaxy.html#_exploit_kit) and all the [galaxy which can be mapped](/galaxy.html), course-of-action SDO added. Export code has been improved to cope with the utter complex mess of STIX patterning standard.
|
||||
|
||||
The STIX 1.x export now includes reporter in STIX incident and producer in STIX indicator and MISP TLP Marking as STIX tlpMarking. File objects are now included in STIX 1.x export.
|
||||
|
||||
|
|
|
@ -32,10 +32,10 @@ The advanced sighting view on objects is now properly working.
|
|||
|
||||
New attribute types were introduced in MISP in order to improve the support of new or improved objects:
|
||||
|
||||
- x509-fingerprint-sha256 - to support the updated [x509 object](https://www.misp-project.org/objects.html#_x509)
|
||||
- x509-fingerprint-md5 - to support the updated [x509 object](https://www.misp-project.org/objects.html#_x509)
|
||||
- stix2-pattern - to a new [stix2-pattern object](https://www.misp-project.org/objects.html#_stix2_pattern)
|
||||
- whois-registrant-org - to support the updated [whois object](https://www.misp-project.org/objects.html#_whois)
|
||||
- x509-fingerprint-sha256 - to support the updated [x509 object](/objects.html#_x509)
|
||||
- x509-fingerprint-md5 - to support the updated [x509 object](/objects.html#_x509)
|
||||
- stix2-pattern - to a new [stix2-pattern object](/objects.html#_stix2_pattern)
|
||||
- whois-registrant-org - to support the updated [whois object](/objects.html#_whois)
|
||||
|
||||
The STIX 2.0 export had undergone significant improvements to support the full mapping between the MISP and STIX 2.0 standards.
|
||||
If a mapping is not supported in the STIX 2.0 standard, we also export custom objects to allow organisations to still receive
|
||||
|
|
|
@ -10,7 +10,7 @@ A new version of MISP [2.4.87](https://github.com/MISP/MISP/tree/v2.4.87) has be
|
|||
The feed system now supports the ability to add any arbitrary HTTP headers which can be used to cache and get feeds from feed providers with authentication. A basic authentication widget has been added to easily generate the appropriate
|
||||
authentication header for a feed. Feed providers are more than welcome to contact us, if they would like to have their feed metadata added to the default MISP installation.
|
||||
|
||||
The MISP ZMQ publish-subscribe channel has been extended with a new specific channel for all activities related to [tags](https://www.misp-project.org/taxonomies.html).
|
||||
The MISP ZMQ publish-subscribe channel has been extended with a new specific channel for all activities related to [tags](/taxonomies.html).
|
||||
|
||||
[Warning-list](https://github.com/MISP/misp-warninglists) can now support a regular expressions in addition to the string, substring, hostname and CIDR parsing algorithms. This allows the creation of a new type of versatile of warning-lists, which can be used to filter false-positives at the API level (using the `enforcewarninglist` option in the API) and to limit the export of false-positives.
|
||||
|
||||
|
|
|
@ -9,7 +9,7 @@ A new version of MISP [2.4.88](https://github.com/MISP/MISP/tree/v2.4.88) has be
|
|||
|
||||
Fuzzy hashing (e.g ssdeep or tlsh) is a commonly used technique used to classify malware, binaries or even text. The MISP correlation engine has always been supporting a simple yet powerful matchinging algorithm to find similar attributes. After an training insightful session in Austria with Manfred Kaiser working at bmlv.gv.at and based on the previous work of [Brian Wallace](https://github.com/bwall) on ssdeep clustering, MISP 2.4.88 introduces the ability to correlate similar binaries (or just their values) using fuzzy hashing via ssdeep. In addition to the standard and advanced correlation algorithms (e.g. CDIR block matching) in MISP, fuzzy hashing correlation allows the matching of similarities among a set of binaries. The installation of the feature is described in the [README.install](https://github.com/MISP/MISP/blob/2.4/INSTALL/INSTALL.ubuntu1604.txt#L316) and don't forget to set the correlation threshold for ssdeep in MISP serverSetttings (e.g. MISP.ssdeep_correlation_threshold).
|
||||
|
||||
As of 2.4.88, MISP supports STIX 1.1.1 XML import from the user-interface similarly to how MISP JSON format data is used to create new events. We hope this will help users to import existing threat intelligence from other sources and benefit from the MISP standard format functionality. If you have any issues with import functionalities feel free to [send us sample STIX 1.1.1 files](https://www.misp-project.org/who/#contact).
|
||||
As of 2.4.88, MISP supports STIX 1.1.1 XML import from the user-interface similarly to how MISP JSON format data is used to create new events. We hope this will help users to import existing threat intelligence from other sources and benefit from the MISP standard format functionality. If you have any issues with import functionalities feel free to [send us sample STIX 1.1.1 files](/who/#contact).
|
||||
|
||||
The workflow for merging organisations has been improved to make it more intuitive for the administrators of the MISP instance.
|
||||
|
||||
|
|
|
@ -7,7 +7,7 @@ banner: /img/blog/misp-small.png
|
|||
|
||||
A new version of MISP [2.4.93](https://github.com/MISP/MISP/tree/v2.4.93) has been released including a much improved and tightly integrated [MITRE ATT&CK](https://attack.mitre.org) interface, a new event locking functionality, initial support for a multilingual interface, various fixes including a security fix ([CVE-2018-12649](https://cve.circl.lu/cve/CVE-2018-12649)).
|
||||
|
||||
MITRE ATT&CK offers an excellent, efficient and very complete framework to describe adversarial tactics and techniques, which MISP now directly incorporates as a way to contextualise the information contained within (at the event and attribute levels) and to share the contextualised data with your partners. We have been supporting the use of the ATT&CK framework via the [misp-galaxy](https://www.misp-project.org/galaxy.html) from the early beginning but we quickly realised the limitations of using this technique in MISP. So we decided to improve the user-interface by having the ATT&CK matrix directly accessible in MISP in order to be able to more intuitively attach techniques and tactics to MISP data following a method that is more universally linked to ATT&CK. The global statistics were also extended in order to get a quick overview of techniques used.
|
||||
MITRE ATT&CK offers an excellent, efficient and very complete framework to describe adversarial tactics and techniques, which MISP now directly incorporates as a way to contextualise the information contained within (at the event and attribute levels) and to share the contextualised data with your partners. We have been supporting the use of the ATT&CK framework via the [misp-galaxy](/galaxy.html) from the early beginning but we quickly realised the limitations of using this technique in MISP. So we decided to improve the user-interface by having the ATT&CK matrix directly accessible in MISP in order to be able to more intuitively attach techniques and tactics to MISP data following a method that is more universally linked to ATT&CK. The global statistics were also extended in order to get a quick overview of techniques used.
|
||||
|
||||
<div class="myvideo">
|
||||
<video style="display:block; width:100%; height:auto;" autoplay controls loop="loop">
|
||||
|
|
|
@ -7,17 +7,17 @@ banner: /img/blog/misp-small.png
|
|||
|
||||
A new version of MISP ([2.4.97](https://github.com/MISP/MISP/tree/v2.4.97)) has been released with new features such as related tags, the sighting restSearch API, a new French localisation along with many improvements to the API and he import/export capabilities, such as improved support for [DHS AIS](https://www.us-cert.gov/ais) STIX 1 files.
|
||||
|
||||

|
||||

|
||||
|
||||
The new related tags functionality has been introduced to allow users to view the most commonly used tags for a specific attribute across all events. This can help analysts when deciding to use a specific classification based on previous analyses to reduce the time it takes to contextualise the new information.
|
||||
|
||||

|
||||

|
||||
|
||||
A new API has been introduced, allowing users to search [MISP sightings](https://www.misp.software/2017/02/16/Sighting-The-Next-Level.html) using a set of filter parameters along with a list of data formats (JSON, CSV or XML). The search is available on an event, attribute or instance level. You can easily search by time ranges (from, to or last) using the standard restSearch API syntax.
|
||||
|
||||
At the API level, many changes were introduced such as:
|
||||
|
||||
- [Galaxy](https://www.misp-project.org/galaxy.html) API is now exposed and can be browsed via the API.
|
||||
- [Galaxy](/galaxy.html) API is now exposed and can be browsed via the API.
|
||||
- Event index API can now be exported in CSV format in addition to standard JSON format.
|
||||
- Log entries are now exposed via the API. The API is documented via the template system/REST client.
|
||||
- The Warning-list lookups are now exposed to the API. A value can be quickly tested against the warning-lists enabled on a MISP instance without the need to create any persistent data.
|
||||
|
|
|
@ -14,8 +14,8 @@ The output of the search interface is now consistent with standard attributes vi
|
|||
|
||||
A new experimental import functionality has been included to import SleuthKit mactime timelines from MISP directly. The user can import one or more mactime timelines in MISP, which will be included as a mactime object to describe forensic activities on an analysed file system. The import is a two-step process where the user can cherry pick the forensic events which took place and select the meaningful activity to be added in a MISP event.
|
||||
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
The API has been improved with many new features such as:
|
||||
|
||||
|
|
|
@ -48,7 +48,7 @@ At its core MISP is an automated correlation engine. It assists analysts in fin
|
|||
|
||||

|
||||
|
||||
Our first achievement was the integration of the [AM!TT Framework](https://github.com/misinfosecproject/amitt_framework) as a [MISP Galaxy](https://www.misp-project.org/galaxy.html#_misinformation_pattern). It contains the tags and definitions needed for describing the misinformation tactics and techniques present in a specific information operation.
|
||||
Our first achievement was the integration of the [AM!TT Framework](https://github.com/misinfosecproject/amitt_framework) as a [MISP Galaxy](/galaxy.html#_misinformation_pattern). It contains the tags and definitions needed for describing the misinformation tactics and techniques present in a specific information operation.
|
||||
|
||||
|
||||
## AM!TT Navigatord
|
||||
|
|
|
@ -16,7 +16,7 @@ The recommended technique for coping with this limitation is to externalise the
|
|||
In this article we will be using visualisation techniques to help us better explore cyber threat information shared through [MISP](https://github.com/MISP/MISP) and tagged with [MITRE ATT&CK](https://attack.mitre.org/) techniques, all within a visualisation tool called [Maltego](https://www.paterva.com/buy/maltego-clients/maltego.php).
|
||||
|
||||
## Getting started
|
||||
To get started you will need access to a MISP Threat Sharing community, or run your own instance. As a quickstart, you can use the [MISP Training VM](https://www.misp-project.org/download/#virtual-images) and download data from the [CIRCL OSINT feed](https://www.misp-project.org/feeds/#default-feeds-available-in-misp).
|
||||
To get started you will need access to a MISP Threat Sharing community, or run your own instance. As a quickstart, you can use the [MISP Training VM](/download/#virtual-images) and download data from the [CIRCL OSINT feed](/feeds/#default-feeds-available-in-misp).
|
||||
|
||||
You will want to download the [Maltego CE](https://www.paterva.com/buy/maltego-clients/maltego-ce.php) (free, limited) or the [classic](https://www.paterva.com/buy/maltego-clients/maltego.php) (paid) edition and install the open source [MISP-Maltego](https://github.com/MISP/MISP-maltego/blob/master/doc/README.md#installation) transform.
|
||||
|
||||
|
|
|
@ -43,7 +43,7 @@ The NATO Communications and Information (NCI) Agency operates a MISP community,
|
|||
|
||||
### MISP COVID-19 Community
|
||||
|
||||
[COVID-19 MISP Information Sharing Community](https://www.misp-project.org/covid-19-misp/) is available and you can self-register to get access to it.
|
||||
[COVID-19 MISP Information Sharing Community](/covid-19-misp/) is available and you can self-register to get access to it.
|
||||
|
||||
## MISP Feed Communities
|
||||
|
||||
|
|
|
@ -132,7 +132,7 @@ Testing new MISP releases and updates is one of the ways that you can contribute
|
|||
However, you should only attempt to do this if you know what you’re doing. Never rely on code that is in testing for critical work!
|
||||
After your testing, we would be grateful for your feedback via GitHub issues.
|
||||
|
||||
If you would like to test MISP and don’t want to do an installation, you can use automatically-generated VM images. See more on our [download page](https://www.misp-project.org/download/#virtual-images).
|
||||
If you would like to test MISP and don’t want to do an installation, you can use automatically-generated VM images. See more on our [download page](/download/#virtual-images).
|
||||
|
||||
## Translating MISP
|
||||
|
||||
|
|
|
@ -38,7 +38,7 @@ Access can be requested to CIRCL by sending an email to [CIRCL](mailto:info@circ
|
|||
|
||||
- [MISP COVID-19 replay training session](https://bbb.secin.lu/playback/presentation/2.0/playback.html?meetingId=741e7d15e14e107dbfffe2106a8547abc8460f3e-1585312475228)
|
||||
- [MISP COVID-19 Training](https://peertube.opencloud.lu/videos/watch/4f7acd4c-a909-4315-87aa-38ba95cceaf2)
|
||||
- [MISP COVID-19 Slides](https://www.misp-project.org/misp-training/x.5-covid.pdf)
|
||||
- [MISP COVID-19 Slides](/misp-training/x.5-covid.pdf)
|
||||
|
||||
## Public Feeds generated from COVID-19 MISP community
|
||||
|
||||
|
|
|
@ -815,652 +815,652 @@ The taxonomies can be [browsed via the web site](/taxonomies.html) or downloaded
|
|||
### CERT-XLM
|
||||
|
||||
[CERT-XLM](https://github.com/MISP/misp-taxonomies/tree/main/CERT-XLM) :
|
||||
CERT-XLM Security Incident Classification. [Overview](https://www.misp-project.org/taxonomies.html#_CERT_XLM)
|
||||
CERT-XLM Security Incident Classification. [Overview](/taxonomies.html#_CERT_XLM)
|
||||
|
||||
### DFRLab-dichotomies-of-disinformation
|
||||
|
||||
[DFRLab-dichotomies-of-disinformation](https://github.com/MISP/misp-taxonomies/tree/main/DFRLab-dichotomies-of-disinformation) :
|
||||
DFRLab Dichotomies of Disinformation. [Overview](https://www.misp-project.org/taxonomies.html#_DFRLab_dichotomies_of_disinformation)
|
||||
DFRLab Dichotomies of Disinformation. [Overview](/taxonomies.html#_DFRLab_dichotomies_of_disinformation)
|
||||
|
||||
### DML
|
||||
|
||||
[DML](https://github.com/MISP/misp-taxonomies/tree/main/DML) :
|
||||
The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks. It's designed for organizations who perform intel-driven detection and response and who put an emphasis on having a mature detection program. [Overview](https://www.misp-project.org/taxonomies.html#_DML)
|
||||
The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks. It's designed for organizations who perform intel-driven detection and response and who put an emphasis on having a mature detection program. [Overview](/taxonomies.html#_DML)
|
||||
|
||||
### PAP
|
||||
|
||||
[PAP](https://github.com/MISP/misp-taxonomies/tree/main/PAP) :
|
||||
The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used. [Overview](https://www.misp-project.org/taxonomies.html#_PAP)
|
||||
The Permissible Actions Protocol - or short: PAP - was designed to indicate how the received information can be used. [Overview](/taxonomies.html#_PAP)
|
||||
|
||||
### access-method
|
||||
|
||||
[access-method](https://github.com/MISP/misp-taxonomies/tree/main/access-method) :
|
||||
The access method used to remotely access a system. [Overview](https://www.misp-project.org/taxonomies.html#_access_method)
|
||||
The access method used to remotely access a system. [Overview](/taxonomies.html#_access_method)
|
||||
|
||||
### accessnow
|
||||
|
||||
[accessnow](https://github.com/MISP/misp-taxonomies/tree/main/accessnow) :
|
||||
Access Now classification to classify an issue (such as security, human rights, youth rights). [Overview](https://www.misp-project.org/taxonomies.html#_accessnow)
|
||||
Access Now classification to classify an issue (such as security, human rights, youth rights). [Overview](/taxonomies.html#_accessnow)
|
||||
|
||||
### action-taken
|
||||
|
||||
[action-taken](https://github.com/MISP/misp-taxonomies/tree/main/action-taken) :
|
||||
Action taken in the case of a security incident (CSIRT perspective). [Overview](https://www.misp-project.org/taxonomies.html#_action_taken)
|
||||
Action taken in the case of a security incident (CSIRT perspective). [Overview](/taxonomies.html#_action_taken)
|
||||
|
||||
### admiralty-scale
|
||||
|
||||
[admiralty-scale](https://github.com/MISP/misp-taxonomies/tree/main/admiralty-scale) :
|
||||
The Admiralty Scale or Ranking (also called the NATO System) is used to rank the reliability of a source and the credibility of an information. Reference based on FM 2-22.3 (FM 34-52) HUMAN INTELLIGENCE COLLECTOR OPERATIONS and NATO documents. [Overview](https://www.misp-project.org/taxonomies.html#_admiralty_scale)
|
||||
The Admiralty Scale or Ranking (also called the NATO System) is used to rank the reliability of a source and the credibility of an information. Reference based on FM 2-22.3 (FM 34-52) HUMAN INTELLIGENCE COLLECTOR OPERATIONS and NATO documents. [Overview](/taxonomies.html#_admiralty_scale)
|
||||
|
||||
### adversary
|
||||
|
||||
[adversary](https://github.com/MISP/misp-taxonomies/tree/main/adversary) :
|
||||
An overview and description of the adversary infrastructure [Overview](https://www.misp-project.org/taxonomies.html#_adversary)
|
||||
An overview and description of the adversary infrastructure [Overview](/taxonomies.html#_adversary)
|
||||
|
||||
### ais-marking
|
||||
|
||||
[ais-marking](https://github.com/MISP/misp-taxonomies/tree/main/ais-marking) :
|
||||
The AIS Marking Schema implementation is maintained by the National Cybersecurity and Communication Integration Center (NCCIC) of the U.S. Department of Homeland Security (DHS) [Overview](https://www.misp-project.org/taxonomies.html#_ais_marking)
|
||||
The AIS Marking Schema implementation is maintained by the National Cybersecurity and Communication Integration Center (NCCIC) of the U.S. Department of Homeland Security (DHS) [Overview](/taxonomies.html#_ais_marking)
|
||||
|
||||
### analyst-assessment
|
||||
|
||||
[analyst-assessment](https://github.com/MISP/misp-taxonomies/tree/main/analyst-assessment) :
|
||||
A series of assessment predicates describing the analyst capabilities to perform analysis. These assessment can be assigned by the analyst him/herself or by another party evaluating the analyst. [Overview](https://www.misp-project.org/taxonomies.html#_analyst_assessment)
|
||||
A series of assessment predicates describing the analyst capabilities to perform analysis. These assessment can be assigned by the analyst him/herself or by another party evaluating the analyst. [Overview](/taxonomies.html#_analyst_assessment)
|
||||
|
||||
### approved-category-of-action
|
||||
|
||||
[approved-category-of-action](https://github.com/MISP/misp-taxonomies/tree/main/approved-category-of-action) :
|
||||
A pre-approved category of action for indicators being shared with partners (MIMIC). [Overview](https://www.misp-project.org/taxonomies.html#_approved_category_of_action)
|
||||
A pre-approved category of action for indicators being shared with partners (MIMIC). [Overview](/taxonomies.html#_approved_category_of_action)
|
||||
|
||||
### binary-class
|
||||
|
||||
[binary-class](https://github.com/MISP/misp-taxonomies/tree/main/binary-class) :
|
||||
Custom taxonomy for types of binary file. [Overview](https://www.misp-project.org/taxonomies.html#_binary_class)
|
||||
Custom taxonomy for types of binary file. [Overview](/taxonomies.html#_binary_class)
|
||||
|
||||
### cccs
|
||||
|
||||
[cccs](https://github.com/MISP/misp-taxonomies/tree/main/cccs) :
|
||||
Internal taxonomy for CCCS. [Overview](https://www.misp-project.org/taxonomies.html#_cccs)
|
||||
Internal taxonomy for CCCS. [Overview](/taxonomies.html#_cccs)
|
||||
|
||||
### circl
|
||||
|
||||
[circl](https://github.com/MISP/misp-taxonomies/tree/main/circl) :
|
||||
CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection [Overview](https://www.misp-project.org/taxonomies.html#_circl)
|
||||
CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection [Overview](/taxonomies.html#_circl)
|
||||
|
||||
### coa
|
||||
|
||||
[coa](https://github.com/MISP/misp-taxonomies/tree/main/coa) :
|
||||
Course of action taken within organization to discover, detect, deny, disrupt, degrade, deceive and/or destroy an attack. [Overview](https://www.misp-project.org/taxonomies.html#_coa)
|
||||
Course of action taken within organization to discover, detect, deny, disrupt, degrade, deceive and/or destroy an attack. [Overview](/taxonomies.html#_coa)
|
||||
|
||||
### collaborative-intelligence
|
||||
|
||||
[collaborative-intelligence](https://github.com/MISP/misp-taxonomies/tree/main/collaborative-intelligence) :
|
||||
Collaborative intelligence support language is a common language to support analysts to perform their analysis to get crowdsourced support when using threat intelligence sharing platform like MISP. The objective of this language is to advance collaborative analysis and to share earlier than later. [Overview](https://www.misp-project.org/taxonomies.html#_collaborative_intelligence)
|
||||
Collaborative intelligence support language is a common language to support analysts to perform their analysis to get crowdsourced support when using threat intelligence sharing platform like MISP. The objective of this language is to advance collaborative analysis and to share earlier than later. [Overview](/taxonomies.html#_collaborative_intelligence)
|
||||
|
||||
### common-taxonomy
|
||||
|
||||
[common-taxonomy](https://github.com/MISP/misp-taxonomies/tree/main/common-taxonomy) :
|
||||
Common Taxonomy for Law enforcement and CSIRTs [Overview](https://www.misp-project.org/taxonomies.html#_common_taxonomy)
|
||||
Common Taxonomy for Law enforcement and CSIRTs [Overview](/taxonomies.html#_common_taxonomy)
|
||||
|
||||
### copine-scale
|
||||
|
||||
[copine-scale](https://github.com/MISP/misp-taxonomies/tree/main/copine-scale) :
|
||||
The COPINE Scale is a rating system created in Ireland and used in the United Kingdom to categorise the severity of images of child sex abuse. The scale was developed by staff at the COPINE (Combating Paedophile Information Networks in Europe) project. The COPINE Project was founded in 1997, and is based in the Department of Applied Psychology, University College Cork, Ireland. [Overview](https://www.misp-project.org/taxonomies.html#_copine_scale)
|
||||
The COPINE Scale is a rating system created in Ireland and used in the United Kingdom to categorise the severity of images of child sex abuse. The scale was developed by staff at the COPINE (Combating Paedophile Information Networks in Europe) project. The COPINE Project was founded in 1997, and is based in the Department of Applied Psychology, University College Cork, Ireland. [Overview](/taxonomies.html#_copine_scale)
|
||||
|
||||
### course-of-action
|
||||
|
||||
[course-of-action](https://github.com/MISP/misp-taxonomies/tree/main/course-of-action) :
|
||||
A Course Of Action analysis considers six potential courses of action for the development of a cyber security capability. [Overview](https://www.misp-project.org/taxonomies.html#_course_of_action)
|
||||
A Course Of Action analysis considers six potential courses of action for the development of a cyber security capability. [Overview](/taxonomies.html#_course_of_action)
|
||||
|
||||
### cryptocurrency-threat
|
||||
|
||||
[cryptocurrency-threat](https://github.com/MISP/misp-taxonomies/tree/main/cryptocurrency-threat) :
|
||||
Threats targetting cryptocurrency, based on CipherTrace report. [Overview](https://www.misp-project.org/taxonomies.html#_cryptocurrency_threat)
|
||||
Threats targetting cryptocurrency, based on CipherTrace report. [Overview](/taxonomies.html#_cryptocurrency_threat)
|
||||
|
||||
### csirt-americas
|
||||
|
||||
[csirt-americas](https://github.com/MISP/misp-taxonomies/tree/main/csirt-americas) :
|
||||
Taxonomía CSIRT Américas. [Overview](https://www.misp-project.org/taxonomies.html#_csirt_americas)
|
||||
Taxonomía CSIRT Américas. [Overview](/taxonomies.html#_csirt_americas)
|
||||
|
||||
### csirt_case_classification
|
||||
|
||||
[csirt_case_classification](https://github.com/MISP/misp-taxonomies/tree/main/csirt_case_classification) :
|
||||
It is critical that the CSIRT provide consistent and timely response to the customer, and that sensitive information is handled appropriately. This document provides the guidelines needed for CSIRT Incident Managers (IM) to classify the case category, criticality level, and sensitivity level for each CSIRT case. This information will be entered into the Incident Tracking System (ITS) when a case is created. Consistent case classification is required for the CSIRT to provide accurate reporting to management on a regular basis. In addition, the classifications will provide CSIRT IM’s with proper case handling procedures and will form the basis of SLA’s between the CSIRT and other Company departments. [Overview](https://www.misp-project.org/taxonomies.html#_csirt_case_classification)
|
||||
It is critical that the CSIRT provide consistent and timely response to the customer, and that sensitive information is handled appropriately. This document provides the guidelines needed for CSIRT Incident Managers (IM) to classify the case category, criticality level, and sensitivity level for each CSIRT case. This information will be entered into the Incident Tracking System (ITS) when a case is created. Consistent case classification is required for the CSIRT to provide accurate reporting to management on a regular basis. In addition, the classifications will provide CSIRT IM’s with proper case handling procedures and will form the basis of SLA’s between the CSIRT and other Company departments. [Overview](/taxonomies.html#_csirt_case_classification)
|
||||
|
||||
### cssa
|
||||
|
||||
[cssa](https://github.com/MISP/misp-taxonomies/tree/main/cssa) :
|
||||
The CSSA agreed sharing taxonomy. [Overview](https://www.misp-project.org/taxonomies.html#_cssa)
|
||||
The CSSA agreed sharing taxonomy. [Overview](/taxonomies.html#_cssa)
|
||||
|
||||
### cti
|
||||
|
||||
[cti](https://github.com/MISP/misp-taxonomies/tree/main/cti) :
|
||||
Cyber Threat Intelligence cycle to control workflow state of your process. [Overview](https://www.misp-project.org/taxonomies.html#_cti)
|
||||
Cyber Threat Intelligence cycle to control workflow state of your process. [Overview](/taxonomies.html#_cti)
|
||||
|
||||
### current-event
|
||||
|
||||
[current-event](https://github.com/MISP/misp-taxonomies/tree/main/current-event) :
|
||||
Current events - Schemes of Classification in Incident Response and Detection [Overview](https://www.misp-project.org/taxonomies.html#_current_event)
|
||||
Current events - Schemes of Classification in Incident Response and Detection [Overview](/taxonomies.html#_current_event)
|
||||
|
||||
### cyber-threat-framework
|
||||
|
||||
[cyber-threat-framework](https://github.com/MISP/misp-taxonomies/tree/main/cyber-threat-framework) :
|
||||
Cyber Threat Framework was developed by the US Government to enable consistent characterization and categorization of cyber threat events, and to identify trends or changes in the activities of cyber adversaries. https://www.dni.gov/index.php/cyber-threat-framework [Overview](https://www.misp-project.org/taxonomies.html#_cyber_threat_framework)
|
||||
Cyber Threat Framework was developed by the US Government to enable consistent characterization and categorization of cyber threat events, and to identify trends or changes in the activities of cyber adversaries. https://www.dni.gov/index.php/cyber-threat-framework [Overview](/taxonomies.html#_cyber_threat_framework)
|
||||
|
||||
### cycat
|
||||
|
||||
[cycat](https://github.com/MISP/misp-taxonomies/tree/main/cycat) :
|
||||
Taxonomy used by CyCAT, the Universal Cybersecurity Resource Catalogue, to categorize the namespaces it supports and uses. [Overview](https://www.misp-project.org/taxonomies.html#_cycat)
|
||||
Taxonomy used by CyCAT, the Universal Cybersecurity Resource Catalogue, to categorize the namespaces it supports and uses. [Overview](/taxonomies.html#_cycat)
|
||||
|
||||
### cytomic-orion
|
||||
|
||||
[cytomic-orion](https://github.com/MISP/misp-taxonomies/tree/main/cytomic-orion) :
|
||||
Taxonomy to describe desired actions for Cytomic Orion [Overview](https://www.misp-project.org/taxonomies.html#_cytomic_orion)
|
||||
Taxonomy to describe desired actions for Cytomic Orion [Overview](/taxonomies.html#_cytomic_orion)
|
||||
|
||||
### dark-web
|
||||
|
||||
[dark-web](https://github.com/MISP/misp-taxonomies/tree/main/dark-web) :
|
||||
Criminal motivation on the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project [Overview](https://www.misp-project.org/taxonomies.html#_dark_web)
|
||||
Criminal motivation on the dark web: A categorisation model for law enforcement. ref: Janis Dalins, Campbell Wilson, Mark Carman. Taxonomy updated by MISP Project [Overview](/taxonomies.html#_dark_web)
|
||||
|
||||
### data-classification
|
||||
|
||||
[data-classification](https://github.com/MISP/misp-taxonomies/tree/main/data-classification) :
|
||||
Data classification for data potentially at risk of exfiltration based on table 2.1 of Solving Cyber Risk book. [Overview](https://www.misp-project.org/taxonomies.html#_data_classification)
|
||||
Data classification for data potentially at risk of exfiltration based on table 2.1 of Solving Cyber Risk book. [Overview](/taxonomies.html#_data_classification)
|
||||
|
||||
### dcso-sharing
|
||||
|
||||
[dcso-sharing](https://github.com/MISP/misp-taxonomies/tree/main/dcso-sharing) :
|
||||
Taxonomy defined in the DCSO MISP Event Guide. It provides guidance for the creation and consumption of MISP events in a way that minimises the extra effort for the sending party, while enhancing the usefulness for receiving parties. [Overview](https://www.misp-project.org/taxonomies.html#_dcso_sharing)
|
||||
Taxonomy defined in the DCSO MISP Event Guide. It provides guidance for the creation and consumption of MISP events in a way that minimises the extra effort for the sending party, while enhancing the usefulness for receiving parties. [Overview](/taxonomies.html#_dcso_sharing)
|
||||
|
||||
### ddos
|
||||
|
||||
[ddos](https://github.com/MISP/misp-taxonomies/tree/main/ddos) :
|
||||
Distributed Denial of Service - or short: DDoS - taxonomy supports the description of Denial of Service attacks and especially the types they belong too. [Overview](https://www.misp-project.org/taxonomies.html#_ddos)
|
||||
Distributed Denial of Service - or short: DDoS - taxonomy supports the description of Denial of Service attacks and especially the types they belong too. [Overview](/taxonomies.html#_ddos)
|
||||
|
||||
### de-vs
|
||||
|
||||
[de-vs](https://github.com/MISP/misp-taxonomies/tree/main/de-vs) :
|
||||
German (DE) Government classification markings (VS). [Overview](https://www.misp-project.org/taxonomies.html#_de_vs)
|
||||
German (DE) Government classification markings (VS). [Overview](/taxonomies.html#_de_vs)
|
||||
|
||||
### deception
|
||||
|
||||
[deception](https://github.com/MISP/misp-taxonomies/tree/main/deception) :
|
||||
Deception is an important component of information operations, valuable for both offense and defense. [Overview](https://www.misp-project.org/taxonomies.html#_deception)
|
||||
Deception is an important component of information operations, valuable for both offense and defense. [Overview](/taxonomies.html#_deception)
|
||||
|
||||
### dhs-ciip-sectors
|
||||
|
||||
[dhs-ciip-sectors](https://github.com/MISP/misp-taxonomies/tree/main/dhs-ciip-sectors) :
|
||||
DHS critical sectors as in https://www.dhs.gov/critical-infrastructure-sectors [Overview](https://www.misp-project.org/taxonomies.html#_dhs_ciip_sectors)
|
||||
DHS critical sectors as in https://www.dhs.gov/critical-infrastructure-sectors [Overview](/taxonomies.html#_dhs_ciip_sectors)
|
||||
|
||||
### diamond-model
|
||||
|
||||
[diamond-model](https://github.com/MISP/misp-taxonomies/tree/main/diamond-model) :
|
||||
The Diamond Model for Intrusion Analysis establishes the basic atomic element of any intrusion activity, the event, composed of four core features: adversary, infrastructure, capability, and victim. [Overview](https://www.misp-project.org/taxonomies.html#_diamond_model)
|
||||
The Diamond Model for Intrusion Analysis establishes the basic atomic element of any intrusion activity, the event, composed of four core features: adversary, infrastructure, capability, and victim. [Overview](/taxonomies.html#_diamond_model)
|
||||
|
||||
### dni-ism
|
||||
|
||||
[dni-ism](https://github.com/MISP/misp-taxonomies/tree/main/dni-ism) :
|
||||
A subset of Information Security Marking Metadata ISM as required by Executive Order (EO) 13526. As described by DNI.gov as Data Encoding Specifications for Information Security Marking Metadata in Controlled Vocabulary Enumeration Values for ISM [Overview](https://www.misp-project.org/taxonomies.html#_dni_ism)
|
||||
A subset of Information Security Marking Metadata ISM as required by Executive Order (EO) 13526. As described by DNI.gov as Data Encoding Specifications for Information Security Marking Metadata in Controlled Vocabulary Enumeration Values for ISM [Overview](/taxonomies.html#_dni_ism)
|
||||
|
||||
### domain-abuse
|
||||
|
||||
[domain-abuse](https://github.com/MISP/misp-taxonomies/tree/main/domain-abuse) :
|
||||
Domain Name Abuse - taxonomy to tag domain names used for cybercrime. [Overview](https://www.misp-project.org/taxonomies.html#_domain_abuse)
|
||||
Domain Name Abuse - taxonomy to tag domain names used for cybercrime. [Overview](/taxonomies.html#_domain_abuse)
|
||||
|
||||
### drugs
|
||||
|
||||
[drugs](https://github.com/MISP/misp-taxonomies/tree/main/drugs) :
|
||||
A taxonomy based on the superclass and class of drugs. Based on https://www.drugbank.ca/releases/latest [Overview](https://www.misp-project.org/taxonomies.html#_drugs)
|
||||
A taxonomy based on the superclass and class of drugs. Based on https://www.drugbank.ca/releases/latest [Overview](/taxonomies.html#_drugs)
|
||||
|
||||
### economical-impact
|
||||
|
||||
[economical-impact](https://github.com/MISP/misp-taxonomies/tree/main/economical-impact) :
|
||||
Economical impact is a taxonomy to describe the financial impact as positive or negative gain to the tagged information (e.g. data exfiltration loss, a positive gain for an adversary). [Overview](https://www.misp-project.org/taxonomies.html#_economical_impact)
|
||||
Economical impact is a taxonomy to describe the financial impact as positive or negative gain to the tagged information (e.g. data exfiltration loss, a positive gain for an adversary). [Overview](/taxonomies.html#_economical_impact)
|
||||
|
||||
### ecsirt
|
||||
|
||||
[ecsirt](https://github.com/MISP/misp-taxonomies/tree/main/ecsirt) :
|
||||
Incident Classification by the ecsirt.net version mkVI of 31 March 2015 enriched with IntelMQ taxonomy-type mapping. [Overview](https://www.misp-project.org/taxonomies.html#_ecsirt)
|
||||
Incident Classification by the ecsirt.net version mkVI of 31 March 2015 enriched with IntelMQ taxonomy-type mapping. [Overview](/taxonomies.html#_ecsirt)
|
||||
|
||||
### enisa
|
||||
|
||||
[enisa](https://github.com/MISP/misp-taxonomies/tree/main/enisa) :
|
||||
The present threat taxonomy is an initial version that has been developed on the basis of available ENISA material. This material has been used as an ENISA-internal structuring aid for information collection and threat consolidation purposes. It emerged in the time period 2012-2015. [Overview](https://www.misp-project.org/taxonomies.html#_enisa)
|
||||
The present threat taxonomy is an initial version that has been developed on the basis of available ENISA material. This material has been used as an ENISA-internal structuring aid for information collection and threat consolidation purposes. It emerged in the time period 2012-2015. [Overview](/taxonomies.html#_enisa)
|
||||
|
||||
### estimative-language
|
||||
|
||||
[estimative-language](https://github.com/MISP/misp-taxonomies/tree/main/estimative-language) :
|
||||
Estimative language to describe quality and credibility of underlying sources, data, and methodologies based Intelligence Community Directive 203 (ICD 203) and JP 2-0, Joint Intelligence [Overview](https://www.misp-project.org/taxonomies.html#_estimative_language)
|
||||
Estimative language to describe quality and credibility of underlying sources, data, and methodologies based Intelligence Community Directive 203 (ICD 203) and JP 2-0, Joint Intelligence [Overview](/taxonomies.html#_estimative_language)
|
||||
|
||||
### eu-marketop-and-publicadmin
|
||||
|
||||
[eu-marketop-and-publicadmin](https://github.com/MISP/misp-taxonomies/tree/main/eu-marketop-and-publicadmin) :
|
||||
Market operators and public administrations that must comply to some notifications requirements under EU NIS directive [Overview](https://www.misp-project.org/taxonomies.html#_eu_marketop_and_publicadmin)
|
||||
Market operators and public administrations that must comply to some notifications requirements under EU NIS directive [Overview](/taxonomies.html#_eu_marketop_and_publicadmin)
|
||||
|
||||
### eu-nis-sector-and-subsectors
|
||||
|
||||
[eu-nis-sector-and-subsectors](https://github.com/MISP/misp-taxonomies/tree/main/eu-nis-sector-and-subsectors) :
|
||||
Sectors, subsectors, and digital services as identified by the NIS Directive [Overview](https://www.misp-project.org/taxonomies.html#_eu_nis_sector_and_subsectors)
|
||||
Sectors, subsectors, and digital services as identified by the NIS Directive [Overview](/taxonomies.html#_eu_nis_sector_and_subsectors)
|
||||
|
||||
### euci
|
||||
|
||||
[euci](https://github.com/MISP/misp-taxonomies/tree/main/euci) :
|
||||
EU classified information (EUCI) means any information or material designated by a EU security classification, the unauthorised disclosure of which could cause varying degrees of prejudice to the interests of the European Union or of one or more of the Member States. [Overview](https://www.misp-project.org/taxonomies.html#_euci)
|
||||
EU classified information (EUCI) means any information or material designated by a EU security classification, the unauthorised disclosure of which could cause varying degrees of prejudice to the interests of the European Union or of one or more of the Member States. [Overview](/taxonomies.html#_euci)
|
||||
|
||||
### europol-event
|
||||
|
||||
[europol-event](https://github.com/MISP/misp-taxonomies/tree/main/europol-event) :
|
||||
This taxonomy was designed to describe the type of events [Overview](https://www.misp-project.org/taxonomies.html#_europol_event)
|
||||
This taxonomy was designed to describe the type of events [Overview](/taxonomies.html#_europol_event)
|
||||
|
||||
### europol-incident
|
||||
|
||||
[europol-incident](https://github.com/MISP/misp-taxonomies/tree/main/europol-incident) :
|
||||
This taxonomy was designed to describe the type of incidents by class. [Overview](https://www.misp-project.org/taxonomies.html#_europol_incident)
|
||||
This taxonomy was designed to describe the type of incidents by class. [Overview](/taxonomies.html#_europol_incident)
|
||||
|
||||
### event-assessment
|
||||
|
||||
[event-assessment](https://github.com/MISP/misp-taxonomies/tree/main/event-assessment) :
|
||||
A series of assessment predicates describing the event assessment performed to make judgement(s) under a certain level of uncertainty. [Overview](https://www.misp-project.org/taxonomies.html#_event_assessment)
|
||||
A series of assessment predicates describing the event assessment performed to make judgement(s) under a certain level of uncertainty. [Overview](/taxonomies.html#_event_assessment)
|
||||
|
||||
### event-classification
|
||||
|
||||
[event-classification](https://github.com/MISP/misp-taxonomies/tree/main/event-classification) :
|
||||
Classification of events as seen in tools such as RT/IR, MISP and other [Overview](https://www.misp-project.org/taxonomies.html#_event_classification)
|
||||
Classification of events as seen in tools such as RT/IR, MISP and other [Overview](/taxonomies.html#_event_classification)
|
||||
|
||||
### exercise
|
||||
|
||||
[exercise](https://github.com/MISP/misp-taxonomies/tree/main/exercise) :
|
||||
Exercise is a taxonomy to describe if the information is part of one or more cyber or crisis exercise. [Overview](https://www.misp-project.org/taxonomies.html#_exercise)
|
||||
Exercise is a taxonomy to describe if the information is part of one or more cyber or crisis exercise. [Overview](/taxonomies.html#_exercise)
|
||||
|
||||
### extended-event
|
||||
|
||||
[extended-event](https://github.com/MISP/misp-taxonomies/tree/main/extended-event) :
|
||||
Reasons why an event has been extended. [Overview](https://www.misp-project.org/taxonomies.html#_extended_event)
|
||||
Reasons why an event has been extended. [Overview](/taxonomies.html#_extended_event)
|
||||
|
||||
### failure-mode-in-machine-learning
|
||||
|
||||
[failure-mode-in-machine-learning](https://github.com/MISP/misp-taxonomies/tree/main/failure-mode-in-machine-learning) :
|
||||
The purpose of this taxonomy is to jointly tabulate both the of these failure modes in a single place. Intentional failures wherein the failure is caused by an active adversary attempting to subvert the system to attain her goals – either to misclassify the result, infer private training data, or to steal the underlying algorithm. Unintentional failures wherein the failure is because an ML system produces a formally correct but completely unsafe outcome. [Overview](https://www.misp-project.org/taxonomies.html#_failure_mode_in_machine_learning)
|
||||
The purpose of this taxonomy is to jointly tabulate both the of these failure modes in a single place. Intentional failures wherein the failure is caused by an active adversary attempting to subvert the system to attain her goals – either to misclassify the result, infer private training data, or to steal the underlying algorithm. Unintentional failures wherein the failure is because an ML system produces a formally correct but completely unsafe outcome. [Overview](/taxonomies.html#_failure_mode_in_machine_learning)
|
||||
|
||||
### false-positive
|
||||
|
||||
[false-positive](https://github.com/MISP/misp-taxonomies/tree/main/false-positive) :
|
||||
This taxonomy aims to ballpark the expected amount of false positives. [Overview](https://www.misp-project.org/taxonomies.html#_false_positive)
|
||||
This taxonomy aims to ballpark the expected amount of false positives. [Overview](/taxonomies.html#_false_positive)
|
||||
|
||||
### file-type
|
||||
|
||||
[file-type](https://github.com/MISP/misp-taxonomies/tree/main/file-type) :
|
||||
List of known file types. [Overview](https://www.misp-project.org/taxonomies.html#_file_type)
|
||||
List of known file types. [Overview](/taxonomies.html#_file_type)
|
||||
|
||||
### flesch-reading-ease
|
||||
|
||||
[flesch-reading-ease](https://github.com/MISP/misp-taxonomies/tree/main/flesch-reading-ease) :
|
||||
Flesch Reading Ease is a revised system for determining the comprehension difficulty of written material. The scoring of the flesh score can have a maximum of 121.22 and there is no limit on how low a score can be (negative score are valid). [Overview](https://www.misp-project.org/taxonomies.html#_flesch_reading_ease)
|
||||
Flesch Reading Ease is a revised system for determining the comprehension difficulty of written material. The scoring of the flesh score can have a maximum of 121.22 and there is no limit on how low a score can be (negative score are valid). [Overview](/taxonomies.html#_flesch_reading_ease)
|
||||
|
||||
### fpf
|
||||
|
||||
[fpf](https://github.com/MISP/misp-taxonomies/tree/main/fpf) :
|
||||
The Future of Privacy Forum (FPF) [visual guide to practical de-identification](https://fpf.org/2016/04/25/a-visual-guide-to-practical-data-de-identification/) taxonomy is used to evaluate the degree of identifiability of personal data and the types of pseudonymous data, de-identified data and anonymous data. The work of FPF is licensed under a creative commons attribution 4.0 international license. [Overview](https://www.misp-project.org/taxonomies.html#_fpf)
|
||||
The Future of Privacy Forum (FPF) [visual guide to practical de-identification](https://fpf.org/2016/04/25/a-visual-guide-to-practical-data-de-identification/) taxonomy is used to evaluate the degree of identifiability of personal data and the types of pseudonymous data, de-identified data and anonymous data. The work of FPF is licensed under a creative commons attribution 4.0 international license. [Overview](/taxonomies.html#_fpf)
|
||||
|
||||
### fr-classif
|
||||
|
||||
[fr-classif](https://github.com/MISP/misp-taxonomies/tree/main/fr-classif) :
|
||||
French gov information classification system [Overview](https://www.misp-project.org/taxonomies.html#_fr_classif)
|
||||
French gov information classification system [Overview](/taxonomies.html#_fr_classif)
|
||||
|
||||
### gdpr
|
||||
|
||||
[gdpr](https://github.com/MISP/misp-taxonomies/tree/main/gdpr) :
|
||||
Taxonomy related to the REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [Overview](https://www.misp-project.org/taxonomies.html#_gdpr)
|
||||
Taxonomy related to the REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) [Overview](/taxonomies.html#_gdpr)
|
||||
|
||||
### gea-nz-activities
|
||||
|
||||
[gea-nz-activities](https://github.com/MISP/misp-taxonomies/tree/main/gea-nz-activities) :
|
||||
Information needed to track or monitor moments, periods or events that occur over time. This type of information is focused on occurrences that must be tracked for business reasons or represent a specific point in the evolution of ‘The Business’. [Overview](https://www.misp-project.org/taxonomies.html#_gea_nz_activities)
|
||||
Information needed to track or monitor moments, periods or events that occur over time. This type of information is focused on occurrences that must be tracked for business reasons or represent a specific point in the evolution of ‘The Business’. [Overview](/taxonomies.html#_gea_nz_activities)
|
||||
|
||||
### gea-nz-entities
|
||||
|
||||
[gea-nz-entities](https://github.com/MISP/misp-taxonomies/tree/main/gea-nz-entities) :
|
||||
Information relating to instances of entities or things. [Overview](https://www.misp-project.org/taxonomies.html#_gea_nz_entities)
|
||||
Information relating to instances of entities or things. [Overview](/taxonomies.html#_gea_nz_entities)
|
||||
|
||||
### gea-nz-motivators
|
||||
|
||||
[gea-nz-motivators](https://github.com/MISP/misp-taxonomies/tree/main/gea-nz-motivators) :
|
||||
Information relating to authority or governance. [Overview](https://www.misp-project.org/taxonomies.html#_gea_nz_motivators)
|
||||
Information relating to authority or governance. [Overview](/taxonomies.html#_gea_nz_motivators)
|
||||
|
||||
### gsma-attack-category
|
||||
|
||||
[gsma-attack-category](https://github.com/MISP/misp-taxonomies/tree/main/gsma-attack-category) :
|
||||
Taxonomy used by GSMA for their information sharing program with telco describing the attack categories [Overview](https://www.misp-project.org/taxonomies.html#_gsma_attack_category)
|
||||
Taxonomy used by GSMA for their information sharing program with telco describing the attack categories [Overview](/taxonomies.html#_gsma_attack_category)
|
||||
|
||||
### gsma-fraud
|
||||
|
||||
[gsma-fraud](https://github.com/MISP/misp-taxonomies/tree/main/gsma-fraud) :
|
||||
Taxonomy used by GSMA for their information sharing program with telco describing the various aspects of fraud [Overview](https://www.misp-project.org/taxonomies.html#_gsma_fraud)
|
||||
Taxonomy used by GSMA for their information sharing program with telco describing the various aspects of fraud [Overview](/taxonomies.html#_gsma_fraud)
|
||||
|
||||
### gsma-network-technology
|
||||
|
||||
[gsma-network-technology](https://github.com/MISP/misp-taxonomies/tree/main/gsma-network-technology) :
|
||||
Taxonomy used by GSMA for their information sharing program with telco describing the types of infrastructure. WiP [Overview](https://www.misp-project.org/taxonomies.html#_gsma_network_technology)
|
||||
Taxonomy used by GSMA for their information sharing program with telco describing the types of infrastructure. WiP [Overview](/taxonomies.html#_gsma_network_technology)
|
||||
|
||||
### honeypot-basic
|
||||
|
||||
[honeypot-basic](https://github.com/MISP/misp-taxonomies/tree/main/honeypot-basic) :
|
||||
Updated (CIRCL, Seamus Dowling and EURECOM) from Christian Seifert, Ian Welch, Peter Komisarczuk, ‘Taxonomy of Honeypots’, Technical Report CS-TR-06/12, VICTORIA UNIVERSITY OF WELLINGTON, School of Mathematical and Computing Sciences, June 2006, http://www.mcs.vuw.ac.nz/comp/Publications/archive/CS-TR-06/CS-TR-06-12.pdf [Overview](https://www.misp-project.org/taxonomies.html#_honeypot_basic)
|
||||
Updated (CIRCL, Seamus Dowling and EURECOM) from Christian Seifert, Ian Welch, Peter Komisarczuk, ‘Taxonomy of Honeypots’, Technical Report CS-TR-06/12, VICTORIA UNIVERSITY OF WELLINGTON, School of Mathematical and Computing Sciences, June 2006, http://www.mcs.vuw.ac.nz/comp/Publications/archive/CS-TR-06/CS-TR-06-12.pdf [Overview](/taxonomies.html#_honeypot_basic)
|
||||
|
||||
### ics
|
||||
|
||||
[ics](https://github.com/MISP/misp-taxonomies/tree/main/ics) :
|
||||
FIRST.ORG CTI SIG - MISP Proposal for ICS/OT Threat Attribution (IOC) Project [Overview](https://www.misp-project.org/taxonomies.html#_ics)
|
||||
FIRST.ORG CTI SIG - MISP Proposal for ICS/OT Threat Attribution (IOC) Project [Overview](/taxonomies.html#_ics)
|
||||
|
||||
### iep
|
||||
|
||||
[iep](https://github.com/MISP/misp-taxonomies/tree/main/iep) :
|
||||
Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) framework [Overview](https://www.misp-project.org/taxonomies.html#_iep)
|
||||
Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) framework [Overview](/taxonomies.html#_iep)
|
||||
|
||||
### iep2-policy
|
||||
|
||||
[iep2-policy](https://github.com/MISP/misp-taxonomies/tree/main/iep2-policy) :
|
||||
Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) v2.0 Policy [Overview](https://www.misp-project.org/taxonomies.html#_iep2_policy)
|
||||
Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) v2.0 Policy [Overview](/taxonomies.html#_iep2_policy)
|
||||
|
||||
### iep2-reference
|
||||
|
||||
[iep2-reference](https://github.com/MISP/misp-taxonomies/tree/main/iep2-reference) :
|
||||
Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) v2.0 Reference [Overview](https://www.misp-project.org/taxonomies.html#_iep2_reference)
|
||||
Forum of Incident Response and Security Teams (FIRST) Information Exchange Policy (IEP) v2.0 Reference [Overview](/taxonomies.html#_iep2_reference)
|
||||
|
||||
### ifx-vetting
|
||||
|
||||
[ifx-vetting](https://github.com/MISP/misp-taxonomies/tree/main/ifx-vetting) :
|
||||
The IFX taxonomy is used to categorise information (MISP events and attributes) to aid in the intelligence vetting process [Overview](https://www.misp-project.org/taxonomies.html#_ifx_vetting)
|
||||
The IFX taxonomy is used to categorise information (MISP events and attributes) to aid in the intelligence vetting process [Overview](/taxonomies.html#_ifx_vetting)
|
||||
|
||||
### incident-disposition
|
||||
|
||||
[incident-disposition](https://github.com/MISP/misp-taxonomies/tree/main/incident-disposition) :
|
||||
How an incident is classified in its process to be resolved. The taxonomy is inspired from NASA Incident Response and Management Handbook. https://www.nasa.gov/pdf/589502main_ITS-HBK-2810.09-02%20%5bNASA%20Information%20Security%20Incident%20Management%5d.pdf#page=9 [Overview](https://www.misp-project.org/taxonomies.html#_incident_disposition)
|
||||
How an incident is classified in its process to be resolved. The taxonomy is inspired from NASA Incident Response and Management Handbook. https://www.nasa.gov/pdf/589502main_ITS-HBK-2810.09-02%20%5bNASA%20Information%20Security%20Incident%20Management%5d.pdf#page=9 [Overview](/taxonomies.html#_incident_disposition)
|
||||
|
||||
### infoleak
|
||||
|
||||
[infoleak](https://github.com/MISP/misp-taxonomies/tree/main/infoleak) :
|
||||
A taxonomy describing information leaks and especially information classified as being potentially leaked. The taxonomy is based on the work by CIRCL on the AIL framework. The taxonomy aim is to be used at large to improve classification of leaked information. [Overview](https://www.misp-project.org/taxonomies.html#_infoleak)
|
||||
A taxonomy describing information leaks and especially information classified as being potentially leaked. The taxonomy is based on the work by CIRCL on the AIL framework. The taxonomy aim is to be used at large to improve classification of leaked information. [Overview](/taxonomies.html#_infoleak)
|
||||
|
||||
### information-security-data-source
|
||||
|
||||
[information-security-data-source](https://github.com/MISP/misp-taxonomies/tree/main/information-security-data-source) :
|
||||
Taxonomy to classify the information security data sources. [Overview](https://www.misp-project.org/taxonomies.html#_information_security_data_source)
|
||||
Taxonomy to classify the information security data sources. [Overview](/taxonomies.html#_information_security_data_source)
|
||||
|
||||
### information-security-indicators
|
||||
|
||||
[information-security-indicators](https://github.com/MISP/misp-taxonomies/tree/main/information-security-indicators) :
|
||||
A full set of operational indicators for organizations to use to benchmark their security posture. [Overview](https://www.misp-project.org/taxonomies.html#_information_security_indicators)
|
||||
A full set of operational indicators for organizations to use to benchmark their security posture. [Overview](/taxonomies.html#_information_security_indicators)
|
||||
|
||||
### interactive-cyber-training-audience
|
||||
|
||||
[interactive-cyber-training-audience](https://github.com/MISP/misp-taxonomies/tree/main/interactive-cyber-training-audience) :
|
||||
Describes the target of cyber training and education. [Overview](https://www.misp-project.org/taxonomies.html#_interactive_cyber_training_audience)
|
||||
Describes the target of cyber training and education. [Overview](/taxonomies.html#_interactive_cyber_training_audience)
|
||||
|
||||
### interactive-cyber-training-technical-setup
|
||||
|
||||
[interactive-cyber-training-technical-setup](https://github.com/MISP/misp-taxonomies/tree/main/interactive-cyber-training-technical-setup) :
|
||||
The technical setup consists of environment structure, deployment, and orchestration. [Overview](https://www.misp-project.org/taxonomies.html#_interactive_cyber_training_technical_setup)
|
||||
The technical setup consists of environment structure, deployment, and orchestration. [Overview](/taxonomies.html#_interactive_cyber_training_technical_setup)
|
||||
|
||||
### interactive-cyber-training-training-environment
|
||||
|
||||
[interactive-cyber-training-training-environment](https://github.com/MISP/misp-taxonomies/tree/main/interactive-cyber-training-training-environment) :
|
||||
The training environment details the environment around the training, consisting of training type and scenario. [Overview](https://www.misp-project.org/taxonomies.html#_interactive_cyber_training_training_environment)
|
||||
The training environment details the environment around the training, consisting of training type and scenario. [Overview](/taxonomies.html#_interactive_cyber_training_training_environment)
|
||||
|
||||
### interactive-cyber-training-training-setup
|
||||
|
||||
[interactive-cyber-training-training-setup](https://github.com/MISP/misp-taxonomies/tree/main/interactive-cyber-training-training-setup) :
|
||||
The training setup further describes the training itself with the scoring, roles, the training mode as well as the customization level. [Overview](https://www.misp-project.org/taxonomies.html#_interactive_cyber_training_training_setup)
|
||||
The training setup further describes the training itself with the scoring, roles, the training mode as well as the customization level. [Overview](/taxonomies.html#_interactive_cyber_training_training_setup)
|
||||
|
||||
### interception-method
|
||||
|
||||
[interception-method](https://github.com/MISP/misp-taxonomies/tree/main/interception-method) :
|
||||
The interception method used to intercept traffic. [Overview](https://www.misp-project.org/taxonomies.html#_interception_method)
|
||||
The interception method used to intercept traffic. [Overview](/taxonomies.html#_interception_method)
|
||||
|
||||
### ioc
|
||||
|
||||
[ioc](https://github.com/MISP/misp-taxonomies/tree/main/ioc) :
|
||||
An IOC classification to facilitate automation of malicious and non malicious artifacts [Overview](https://www.misp-project.org/taxonomies.html#_ioc)
|
||||
An IOC classification to facilitate automation of malicious and non malicious artifacts [Overview](/taxonomies.html#_ioc)
|
||||
|
||||
### iot
|
||||
|
||||
[iot](https://github.com/MISP/misp-taxonomies/tree/main/iot) :
|
||||
Internet of Things taxonomy, based on IOT UK report https://iotuk.org.uk/wp-content/uploads/2017/01/IOT-Taxonomy-Report.pdf [Overview](https://www.misp-project.org/taxonomies.html#_iot)
|
||||
Internet of Things taxonomy, based on IOT UK report https://iotuk.org.uk/wp-content/uploads/2017/01/IOT-Taxonomy-Report.pdf [Overview](/taxonomies.html#_iot)
|
||||
|
||||
### kill-chain
|
||||
|
||||
[kill-chain](https://github.com/MISP/misp-taxonomies/tree/main/kill-chain) :
|
||||
The Cyber Kill Chain, a phase-based model developed by Lockheed Martin, aims to help categorise and identify the stage of an attack. [Overview](https://www.misp-project.org/taxonomies.html#_kill_chain)
|
||||
The Cyber Kill Chain, a phase-based model developed by Lockheed Martin, aims to help categorise and identify the stage of an attack. [Overview](/taxonomies.html#_kill_chain)
|
||||
|
||||
### maec-delivery-vectors
|
||||
|
||||
[maec-delivery-vectors](https://github.com/MISP/misp-taxonomies/tree/main/maec-delivery-vectors) :
|
||||
Vectors used to deliver malware based on MAEC 5.0 [Overview](https://www.misp-project.org/taxonomies.html#_maec_delivery_vectors)
|
||||
Vectors used to deliver malware based on MAEC 5.0 [Overview](/taxonomies.html#_maec_delivery_vectors)
|
||||
|
||||
### maec-malware-behavior
|
||||
|
||||
[maec-malware-behavior](https://github.com/MISP/misp-taxonomies/tree/main/maec-malware-behavior) :
|
||||
Malware behaviours based on MAEC 5.0 [Overview](https://www.misp-project.org/taxonomies.html#_maec_malware_behavior)
|
||||
Malware behaviours based on MAEC 5.0 [Overview](/taxonomies.html#_maec_malware_behavior)
|
||||
|
||||
### maec-malware-capabilities
|
||||
|
||||
[maec-malware-capabilities](https://github.com/MISP/misp-taxonomies/tree/main/maec-malware-capabilities) :
|
||||
Malware Capabilities based on MAEC 5.0 [Overview](https://www.misp-project.org/taxonomies.html#_maec_malware_capabilities)
|
||||
Malware Capabilities based on MAEC 5.0 [Overview](/taxonomies.html#_maec_malware_capabilities)
|
||||
|
||||
### maec-malware-obfuscation-methods
|
||||
|
||||
[maec-malware-obfuscation-methods](https://github.com/MISP/misp-taxonomies/tree/main/maec-malware-obfuscation-methods) :
|
||||
Obfuscation methods used by malware based on MAEC 5.0 [Overview](https://www.misp-project.org/taxonomies.html#_maec_malware_obfuscation_methods)
|
||||
Obfuscation methods used by malware based on MAEC 5.0 [Overview](/taxonomies.html#_maec_malware_obfuscation_methods)
|
||||
|
||||
### malware_classification
|
||||
|
||||
[malware_classification](https://github.com/MISP/misp-taxonomies/tree/main/malware_classification) :
|
||||
Classification based on different categories. Based on https://www.sans.org/reading-room/whitepapers/incident/malware-101-viruses-32848 [Overview](https://www.misp-project.org/taxonomies.html#_malware_classification)
|
||||
Classification based on different categories. Based on https://www.sans.org/reading-room/whitepapers/incident/malware-101-viruses-32848 [Overview](/taxonomies.html#_malware_classification)
|
||||
|
||||
### misinformation-website-label
|
||||
|
||||
[misinformation-website-label](https://github.com/MISP/misp-taxonomies/tree/main/misinformation-website-label) :
|
||||
classification for the identification of type of misinformation among websites. Source:False, Misleading, Clickbait-y, and/or Satirical News Sources by Melissa Zimdars 2019 [Overview](https://www.misp-project.org/taxonomies.html#_misinformation_website_label)
|
||||
classification for the identification of type of misinformation among websites. Source:False, Misleading, Clickbait-y, and/or Satirical News Sources by Melissa Zimdars 2019 [Overview](/taxonomies.html#_misinformation_website_label)
|
||||
|
||||
### misp
|
||||
|
||||
[misp](https://github.com/MISP/misp-taxonomies/tree/main/misp) :
|
||||
MISP taxonomy to infer with MISP behavior or operation. [Overview](https://www.misp-project.org/taxonomies.html#_misp)
|
||||
MISP taxonomy to infer with MISP behavior or operation. [Overview](/taxonomies.html#_misp)
|
||||
|
||||
### monarc-threat
|
||||
|
||||
[monarc-threat](https://github.com/MISP/misp-taxonomies/tree/main/monarc-threat) :
|
||||
MONARC Threats Taxonomy [Overview](https://www.misp-project.org/taxonomies.html#_monarc_threat)
|
||||
MONARC Threats Taxonomy [Overview](/taxonomies.html#_monarc_threat)
|
||||
|
||||
### ms-caro-malware
|
||||
|
||||
[ms-caro-malware](https://github.com/MISP/misp-taxonomies/tree/main/ms-caro-malware) :
|
||||
Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families. [Overview](https://www.misp-project.org/taxonomies.html#_ms_caro_malware)
|
||||
Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families. [Overview](/taxonomies.html#_ms_caro_malware)
|
||||
|
||||
### ms-caro-malware-full
|
||||
|
||||
[ms-caro-malware-full](https://github.com/MISP/misp-taxonomies/tree/main/ms-caro-malware-full) :
|
||||
Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families. [Overview](https://www.misp-project.org/taxonomies.html#_ms_caro_malware_full)
|
||||
Malware Type and Platform classification based on Microsoft's implementation of the Computer Antivirus Research Organization (CARO) Naming Scheme and Malware Terminology. Based on https://www.microsoft.com/en-us/security/portal/mmpc/shared/malwarenaming.aspx, https://www.microsoft.com/security/portal/mmpc/shared/glossary.aspx, https://www.microsoft.com/security/portal/mmpc/shared/objectivecriteria.aspx, and http://www.caro.org/definitions/index.html. Malware families are extracted from Microsoft SIRs since 2008 based on https://www.microsoft.com/security/sir/archive/default.aspx and https://www.microsoft.com/en-us/security/portal/threat/threats.aspx. Note that SIRs do NOT include all Microsoft malware families. [Overview](/taxonomies.html#_ms_caro_malware_full)
|
||||
|
||||
### mwdb
|
||||
|
||||
[mwdb](https://github.com/MISP/misp-taxonomies/tree/main/mwdb) :
|
||||
Malware Database (mwdb) Taxonomy - Tags used across the platform [Overview](https://www.misp-project.org/taxonomies.html#_mwdb)
|
||||
Malware Database (mwdb) Taxonomy - Tags used across the platform [Overview](/taxonomies.html#_mwdb)
|
||||
|
||||
### nato
|
||||
|
||||
[nato](https://github.com/MISP/misp-taxonomies/tree/main/nato) :
|
||||
NATO classification markings. [Overview](https://www.misp-project.org/taxonomies.html#_nato)
|
||||
NATO classification markings. [Overview](/taxonomies.html#_nato)
|
||||
|
||||
### nis
|
||||
|
||||
[nis](https://github.com/MISP/misp-taxonomies/tree/main/nis) :
|
||||
The taxonomy is meant for large scale cybersecurity incidents, as mentioned in the Commission Recommendation of 13 September 2017, also known as the blueprint. It has two core parts: The nature of the incident, i.e. the underlying cause, that triggered the incident, and the impact of the incident, i.e. the impact on services, in which sector(s) of economy and society. [Overview](https://www.misp-project.org/taxonomies.html#_nis)
|
||||
The taxonomy is meant for large scale cybersecurity incidents, as mentioned in the Commission Recommendation of 13 September 2017, also known as the blueprint. It has two core parts: The nature of the incident, i.e. the underlying cause, that triggered the incident, and the impact of the incident, i.e. the impact on services, in which sector(s) of economy and society. [Overview](/taxonomies.html#_nis)
|
||||
|
||||
### open_threat
|
||||
|
||||
[open_threat](https://github.com/MISP/misp-taxonomies/tree/main/open_threat) :
|
||||
Open Threat Taxonomy v1.1 base on James Tarala of SANS http://www.auditscripts.com/resources/open_threat_taxonomy_v1.1a.pdf, https://files.sans.org/summit/Threat_Hunting_Incident_Response_Summit_2016/PDFs/Using-Open-Tools-to-Convert-Threat-Intelligence-into-Practical-Defenses-James-Tarala-SANS-Institute.pdf, https://www.youtube.com/watch?v=5rdGOOFC_yE, and https://www.rsaconference.com/writable/presentations/file_upload/str-r04_using-an-open-source-threat-model-for-prioritized-defense-final.pdf [Overview](https://www.misp-project.org/taxonomies.html#_open_threat)
|
||||
Open Threat Taxonomy v1.1 base on James Tarala of SANS http://www.auditscripts.com/resources/open_threat_taxonomy_v1.1a.pdf, https://files.sans.org/summit/Threat_Hunting_Incident_Response_Summit_2016/PDFs/Using-Open-Tools-to-Convert-Threat-Intelligence-into-Practical-Defenses-James-Tarala-SANS-Institute.pdf, https://www.youtube.com/watch?v=5rdGOOFC_yE, and https://www.rsaconference.com/writable/presentations/file_upload/str-r04_using-an-open-source-threat-model-for-prioritized-defense-final.pdf [Overview](/taxonomies.html#_open_threat)
|
||||
|
||||
### osint
|
||||
|
||||
[osint](https://github.com/MISP/misp-taxonomies/tree/main/osint) :
|
||||
Open Source Intelligence - Classification (MISP taxonomies) [Overview](https://www.misp-project.org/taxonomies.html#_osint)
|
||||
Open Source Intelligence - Classification (MISP taxonomies) [Overview](/taxonomies.html#_osint)
|
||||
|
||||
### pandemic
|
||||
|
||||
[pandemic](https://github.com/MISP/misp-taxonomies/tree/main/pandemic) :
|
||||
Pandemic [Overview](https://www.misp-project.org/taxonomies.html#_pandemic)
|
||||
Pandemic [Overview](/taxonomies.html#_pandemic)
|
||||
|
||||
### passivetotal
|
||||
|
||||
[passivetotal](https://github.com/MISP/misp-taxonomies/tree/main/passivetotal) :
|
||||
Tags from RiskIQ's PassiveTotal service [Overview](https://www.misp-project.org/taxonomies.html#_passivetotal)
|
||||
Tags from RiskIQ's PassiveTotal service [Overview](/taxonomies.html#_passivetotal)
|
||||
|
||||
### pentest
|
||||
|
||||
[pentest](https://github.com/MISP/misp-taxonomies/tree/main/pentest) :
|
||||
Penetration test (pentest) classification. [Overview](https://www.misp-project.org/taxonomies.html#_pentest)
|
||||
Penetration test (pentest) classification. [Overview](/taxonomies.html#_pentest)
|
||||
|
||||
### phishing
|
||||
|
||||
[phishing](https://github.com/MISP/misp-taxonomies/tree/main/phishing) :
|
||||
Taxonomy to classify phishing attacks including techniques, collection mechanisms and analysis status. [Overview](https://www.misp-project.org/taxonomies.html#_phishing)
|
||||
Taxonomy to classify phishing attacks including techniques, collection mechanisms and analysis status. [Overview](/taxonomies.html#_phishing)
|
||||
|
||||
### political-spectrum
|
||||
|
||||
[political-spectrum](https://github.com/MISP/misp-taxonomies/tree/main/political-spectrum) :
|
||||
political spectrum is a system to characterize and classify different political positions [Overview](https://www.misp-project.org/taxonomies.html#_political_spectrum)
|
||||
political spectrum is a system to characterize and classify different political positions [Overview](/taxonomies.html#_political_spectrum)
|
||||
|
||||
### priority-level
|
||||
|
||||
[priority-level](https://github.com/MISP/misp-taxonomies/tree/main/priority-level) :
|
||||
After an incident is scored, it is assigned a priority level. The six levels listed below are aligned with NCCIC, DHS, and the CISS to help provide a common lexicon when discussing incidents. This priority assignment drives NCCIC urgency, pre-approved incident response offerings, reporting requirements, and recommendations for leadership escalation. Generally, incident priority distribution should follow a similar pattern to the graph below. Based on https://www.us-cert.gov/NCCIC-Cyber-Incident-Scoring-System. [Overview](https://www.misp-project.org/taxonomies.html#_priority_level)
|
||||
After an incident is scored, it is assigned a priority level. The six levels listed below are aligned with NCCIC, DHS, and the CISS to help provide a common lexicon when discussing incidents. This priority assignment drives NCCIC urgency, pre-approved incident response offerings, reporting requirements, and recommendations for leadership escalation. Generally, incident priority distribution should follow a similar pattern to the graph below. Based on https://www.us-cert.gov/NCCIC-Cyber-Incident-Scoring-System. [Overview](/taxonomies.html#_priority_level)
|
||||
|
||||
### ransomware
|
||||
|
||||
[ransomware](https://github.com/MISP/misp-taxonomies/tree/main/ransomware) :
|
||||
Ransomware is used to define ransomware types and the elements that compose them. [Overview](https://www.misp-project.org/taxonomies.html#_ransomware)
|
||||
Ransomware is used to define ransomware types and the elements that compose them. [Overview](/taxonomies.html#_ransomware)
|
||||
|
||||
### retention
|
||||
|
||||
[retention](https://github.com/MISP/misp-taxonomies/tree/main/retention) :
|
||||
Add a retenion time to events to automatically remove the IDS-flag on ip-dst or ip-src attributes. We calculate the time elapsed based on the date of the event. Supported time units are: d(ays), w(eeks), m(onths), y(ears). The numerical_value is just for sorting in the web-interface and is not used for calculations. [Overview](https://www.misp-project.org/taxonomies.html#_retention)
|
||||
Add a retenion time to events to automatically remove the IDS-flag on ip-dst or ip-src attributes. We calculate the time elapsed based on the date of the event. Supported time units are: d(ays), w(eeks), m(onths), y(ears). The numerical_value is just for sorting in the web-interface and is not used for calculations. [Overview](/taxonomies.html#_retention)
|
||||
|
||||
### rsit
|
||||
|
||||
[rsit](https://github.com/MISP/misp-taxonomies/tree/main/rsit) :
|
||||
Reference Security Incident Classification Taxonomy [Overview](https://www.misp-project.org/taxonomies.html#_rsit)
|
||||
Reference Security Incident Classification Taxonomy [Overview](/taxonomies.html#_rsit)
|
||||
|
||||
### rt_event_status
|
||||
|
||||
[rt_event_status](https://github.com/MISP/misp-taxonomies/tree/main/rt_event_status) :
|
||||
Status of events used in Request Tracker. [Overview](https://www.misp-project.org/taxonomies.html#_rt_event_status)
|
||||
Status of events used in Request Tracker. [Overview](/taxonomies.html#_rt_event_status)
|
||||
|
||||
### runtime-packer
|
||||
|
||||
[runtime-packer](https://github.com/MISP/misp-taxonomies/tree/main/runtime-packer) :
|
||||
Runtime or software packer used to combine compressed data with the decompression code. The decompression code can add additional obfuscations mechanisms including polymorphic-packer or other obfuscation techniques. This taxonomy lists all the known or official packer used for legitimate use or for packing malicious binaries. [Overview](https://www.misp-project.org/taxonomies.html#_runtime_packer)
|
||||
Runtime or software packer used to combine compressed data with the decompression code. The decompression code can add additional obfuscations mechanisms including polymorphic-packer or other obfuscation techniques. This taxonomy lists all the known or official packer used for legitimate use or for packing malicious binaries. [Overview](/taxonomies.html#_runtime_packer)
|
||||
|
||||
### scrippsco2-fgc
|
||||
|
||||
[scrippsco2-fgc](https://github.com/MISP/misp-taxonomies/tree/main/scrippsco2-fgc) :
|
||||
Flags describing the sample [Overview](https://www.misp-project.org/taxonomies.html#_scrippsco2_fgc)
|
||||
Flags describing the sample [Overview](/taxonomies.html#_scrippsco2_fgc)
|
||||
|
||||
### scrippsco2-fgi
|
||||
|
||||
[scrippsco2-fgi](https://github.com/MISP/misp-taxonomies/tree/main/scrippsco2-fgi) :
|
||||
Flags describing the sample for isotopic data (C14, O18) [Overview](https://www.misp-project.org/taxonomies.html#_scrippsco2_fgi)
|
||||
Flags describing the sample for isotopic data (C14, O18) [Overview](/taxonomies.html#_scrippsco2_fgi)
|
||||
|
||||
### scrippsco2-sampling-stations
|
||||
|
||||
[scrippsco2-sampling-stations](https://github.com/MISP/misp-taxonomies/tree/main/scrippsco2-sampling-stations) :
|
||||
Sampling stations of the Scripps CO2 Program [Overview](https://www.misp-project.org/taxonomies.html#_scrippsco2_sampling_stations)
|
||||
Sampling stations of the Scripps CO2 Program [Overview](/taxonomies.html#_scrippsco2_sampling_stations)
|
||||
|
||||
### smart-airports-threats
|
||||
|
||||
[smart-airports-threats](https://github.com/MISP/misp-taxonomies/tree/main/smart-airports-threats) :
|
||||
Threat taxonomy in the scope of securing smart airports by ENISA. https://www.enisa.europa.eu/publications/securing-smart-airports [Overview](https://www.misp-project.org/taxonomies.html#_smart_airports_threats)
|
||||
Threat taxonomy in the scope of securing smart airports by ENISA. https://www.enisa.europa.eu/publications/securing-smart-airports [Overview](/taxonomies.html#_smart_airports_threats)
|
||||
|
||||
### stealth_malware
|
||||
|
||||
[stealth_malware](https://github.com/MISP/misp-taxonomies/tree/main/stealth_malware) :
|
||||
Classification based on malware stealth techniques. Described in https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf [Overview](https://www.misp-project.org/taxonomies.html#_stealth_malware)
|
||||
Classification based on malware stealth techniques. Described in https://vxheaven.org/lib/pdf/Introducing%20Stealth%20Malware%20Taxonomy.pdf [Overview](/taxonomies.html#_stealth_malware)
|
||||
|
||||
### stix-ttp
|
||||
|
||||
[stix-ttp](https://github.com/MISP/misp-taxonomies/tree/main/stix-ttp) :
|
||||
TTPs are representations of the behavior or modus operandi of cyber adversaries. [Overview](https://www.misp-project.org/taxonomies.html#_stix_ttp)
|
||||
TTPs are representations of the behavior or modus operandi of cyber adversaries. [Overview](/taxonomies.html#_stix_ttp)
|
||||
|
||||
### targeted-threat-index
|
||||
|
||||
[targeted-threat-index](https://github.com/MISP/misp-taxonomies/tree/main/targeted-threat-index) :
|
||||
The Targeted Threat Index is a metric for assigning an overall threat ranking score to email messages that deliver malware to a victim’s computer. The TTI metric was first introduced at SecTor 2013 by Seth Hardy as part of the talk “RATastrophe: Monitoring a Malware Menagerie” along with Katie Kleemola and Greg Wiseman. [Overview](https://www.misp-project.org/taxonomies.html#_targeted_threat_index)
|
||||
The Targeted Threat Index is a metric for assigning an overall threat ranking score to email messages that deliver malware to a victim’s computer. The TTI metric was first introduced at SecTor 2013 by Seth Hardy as part of the talk “RATastrophe: Monitoring a Malware Menagerie” along with Katie Kleemola and Greg Wiseman. [Overview](/taxonomies.html#_targeted_threat_index)
|
||||
|
||||
### thales_group
|
||||
|
||||
[thales_group](https://github.com/MISP/misp-taxonomies/tree/main/thales_group) :
|
||||
Thales Group Taxonomy - was designed with the aim of enabling desired sharing and preventing unwanted sharing between Thales Group security communities. [Overview](https://www.misp-project.org/taxonomies.html#_thales_group)
|
||||
Thales Group Taxonomy - was designed with the aim of enabling desired sharing and preventing unwanted sharing between Thales Group security communities. [Overview](/taxonomies.html#_thales_group)
|
||||
|
||||
### threatmatch
|
||||
|
||||
[threatmatch](https://github.com/MISP/misp-taxonomies/tree/main/threatmatch) :
|
||||
The ThreatMatch Sectors, Incident types, Malware types and Alert types are applicable for any ThreatMatch instances and should be used for all CIISI and TIBER Projects. [Overview](https://www.misp-project.org/taxonomies.html#_threatmatch)
|
||||
The ThreatMatch Sectors, Incident types, Malware types and Alert types are applicable for any ThreatMatch instances and should be used for all CIISI and TIBER Projects. [Overview](/taxonomies.html#_threatmatch)
|
||||
|
||||
### threats-to-dns
|
||||
|
||||
[threats-to-dns](https://github.com/MISP/misp-taxonomies/tree/main/threats-to-dns) :
|
||||
An overview of some of the known attacks related to DNS as described by Torabi, S., Boukhtouta, A., Assi, C., & Debbabi, M. (2018) in Detecting Internet Abuse by Analyzing Passive DNS Traffic: A Survey of Implemented Systems. IEEE Communications Surveys & Tutorials, 1–1. doi:10.1109/comst.2018.2849614 [Overview](https://www.misp-project.org/taxonomies.html#_threats_to_dns)
|
||||
An overview of some of the known attacks related to DNS as described by Torabi, S., Boukhtouta, A., Assi, C., & Debbabi, M. (2018) in Detecting Internet Abuse by Analyzing Passive DNS Traffic: A Survey of Implemented Systems. IEEE Communications Surveys & Tutorials, 1–1. doi:10.1109/comst.2018.2849614 [Overview](/taxonomies.html#_threats_to_dns)
|
||||
|
||||
### tlp
|
||||
|
||||
[tlp](https://github.com/MISP/misp-taxonomies/tree/main/tlp) :
|
||||
The Traffic Light Protocol - or short: TLP - was designed with the objective to create a favorable classification scheme for sharing sensitive information while keeping the control over its distribution at the same time. [Overview](https://www.misp-project.org/taxonomies.html#_tlp)
|
||||
The Traffic Light Protocol - or short: TLP - was designed with the objective to create a favorable classification scheme for sharing sensitive information while keeping the control over its distribution at the same time. [Overview](/taxonomies.html#_tlp)
|
||||
|
||||
### tor
|
||||
|
||||
[tor](https://github.com/MISP/misp-taxonomies/tree/main/tor) :
|
||||
Taxonomy to describe Tor network infrastructure [Overview](https://www.misp-project.org/taxonomies.html#_tor)
|
||||
Taxonomy to describe Tor network infrastructure [Overview](/taxonomies.html#_tor)
|
||||
|
||||
### trust
|
||||
|
||||
[trust](https://github.com/MISP/misp-taxonomies/tree/main/trust) :
|
||||
The Indicator of Trust provides insight about data on what can be trusted and known as a good actor. Similar to a whitelist but on steroids, reusing features one would use with Indicators of Compromise, but to filter out what is known to be good. [Overview](https://www.misp-project.org/taxonomies.html#_trust)
|
||||
The Indicator of Trust provides insight about data on what can be trusted and known as a good actor. Similar to a whitelist but on steroids, reusing features one would use with Indicators of Compromise, but to filter out what is known to be good. [Overview](/taxonomies.html#_trust)
|
||||
|
||||
### type
|
||||
|
||||
[type](https://github.com/MISP/misp-taxonomies/tree/main/type) :
|
||||
Taxonomy to describe different types of intelligence gathering discipline which can be described the origin of intelligence. [Overview](https://www.misp-project.org/taxonomies.html#_type)
|
||||
Taxonomy to describe different types of intelligence gathering discipline which can be described the origin of intelligence. [Overview](/taxonomies.html#_type)
|
||||
|
||||
### unified-kill-chain
|
||||
|
||||
[unified-kill-chain](https://github.com/MISP/misp-taxonomies/tree/main/unified-kill-chain) :
|
||||
The Unified Kill Chain is a refinement to the Kill Chain. [Overview](https://www.misp-project.org/taxonomies.html#_unified_kill_chain)
|
||||
The Unified Kill Chain is a refinement to the Kill Chain. [Overview](/taxonomies.html#_unified_kill_chain)
|
||||
|
||||
### use-case-applicability
|
||||
|
||||
[use-case-applicability](https://github.com/MISP/misp-taxonomies/tree/main/use-case-applicability) :
|
||||
The Use Case Applicability categories reflect standard resolution categories, to clearly display alerting rule configuration problems. [Overview](https://www.misp-project.org/taxonomies.html#_use_case_applicability)
|
||||
The Use Case Applicability categories reflect standard resolution categories, to clearly display alerting rule configuration problems. [Overview](/taxonomies.html#_use_case_applicability)
|
||||
|
||||
### veris
|
||||
|
||||
[veris](https://github.com/MISP/misp-taxonomies/tree/main/veris) :
|
||||
Vocabulary for Event Recording and Incident Sharing (VERIS) [Overview](https://www.misp-project.org/taxonomies.html#_veris)
|
||||
Vocabulary for Event Recording and Incident Sharing (VERIS) [Overview](/taxonomies.html#_veris)
|
||||
|
||||
### vmray
|
||||
|
||||
[vmray](https://github.com/MISP/misp-taxonomies/tree/main/vmray) :
|
||||
VMRay taxonomies to map VMRay Thread Identifier scores and artifacts. [Overview](https://www.misp-project.org/taxonomies.html#_vmray)
|
||||
VMRay taxonomies to map VMRay Thread Identifier scores and artifacts. [Overview](/taxonomies.html#_vmray)
|
||||
|
||||
### vocabulaire-des-probabilites-estimatives
|
||||
|
||||
[vocabulaire-des-probabilites-estimatives](https://github.com/MISP/misp-taxonomies/tree/main/vocabulaire-des-probabilites-estimatives) :
|
||||
Ce vocabulaire attribue des valeurs en pourcentage à certains énoncés de probabilité [Overview](https://www.misp-project.org/taxonomies.html#_vocabulaire_des_probabilites_estimatives)
|
||||
Ce vocabulaire attribue des valeurs en pourcentage à certains énoncés de probabilité [Overview](/taxonomies.html#_vocabulaire_des_probabilites_estimatives)
|
||||
|
||||
### workflow
|
||||
|
||||
[workflow](https://github.com/MISP/misp-taxonomies/tree/main/workflow) :
|
||||
Workflow support language is a common language to support intelligence analysts to perform their analysis on data and information. [Overview](https://www.misp-project.org/taxonomies.html#_workflow)
|
||||
Workflow support language is a common language to support intelligence analysts to perform their analysis on data and information. [Overview](/taxonomies.html#_workflow)
|
||||
|
||||
## MISP Galaxy
|
||||
|
||||
|
|
|
@ -23,7 +23,7 @@ MISP Install guides (stock install instructions for getting a base MISP system r
|
|||
|
||||
All MISP training materials (including source code) are available at [https://github.com/MISP/misp-training](https://github.com/MISP/misp-training).
|
||||
|
||||
MISP [training materials are available on](https://www.misp-project.org/misp-training/).
|
||||
MISP [training materials are available on](/misp-training/).
|
||||
|
||||
### MISP format documentation
|
||||
|
||||
|
|
|
@ -12,11 +12,11 @@ Want to join us at an event, discuss opportunities or projects around the MISP p
|
|||
|
||||
### MISP hackathon
|
||||
|
||||
- [Open Source Security Hackathon](https://www.misp-project.org/hackathon/) - pen Source Security hackathon - Monday 25th October 2021 and Tuesday 26th October 2021
|
||||
- [Open Source Security Hackathon](/hackathon/) - pen Source Security hackathon - Monday 25th October 2021 and Tuesday 26th October 2021
|
||||
|
||||
### MISP at conferences
|
||||
|
||||
- [Virtual MISP Summit 0x06](https://www.misp-project.org/misp-summit/) - Thursday 21st October 2021.
|
||||
- [Virtual MISP Summit 0x06](/misp-summit/) - Thursday 21st October 2021.
|
||||
|
||||
### Current MISP Training(s)
|
||||
|
||||
|
|
|
@ -7,13 +7,13 @@ toc: true
|
|||
|
||||
## Announcements and press releases
|
||||
|
||||
The general purpose announcements that we publish are available on the [news page](https://www.misp-project.org/news/).
|
||||
The general purpose announcements that we publish are available on the [news page](/news/).
|
||||
Write us an email at <info@misp-project.org> if you have a press inquiry.
|
||||
You can also send press articles about MISP to this address, so we can add them to this page.
|
||||
|
||||
## Quick links to better understand MISP
|
||||
- More [details about the features](https://www.misp-project.org/features.html) included MISP
|
||||
- Our [data models document](https://www.misp-project.org/datamodels/) about sharing formats used with MISP software
|
||||
- More [details about the features](/features.html) included MISP
|
||||
- Our [data models document](/datamodels/) about sharing formats used with MISP software
|
||||
- Our [documentation](https://www.circl.lu/doc/misp/) explaining in detail how to use MISP
|
||||
|
||||
|
||||
|
@ -35,9 +35,9 @@ MISP is mentioned occasionally in the press. This list is not comprehensive, but
|
|||
| 2013-12-29 | NATO | [Sharing malware information to defeat cyber attacks](https://www.nato.int/cps/en/natolive/news_105485.htm) |
|
||||
|
||||
## Tutorials, trainings and summits
|
||||
- [Some past trainings](https://www.misp-project.org/events/#some-past-misp-trainings)
|
||||
- [Some past trainings](/events/#some-past-misp-trainings)
|
||||
- [Some MISP Training videos](https://www.youtube.com/playlist?list=PLhSWiKucshm4CfNjKm7cxxjmj8LfxRXdp)
|
||||
- [Some MISP Training presentations](https://www.misp-project.org/misp-training/)
|
||||
- [Some MISP Training presentations](/misp-training/)
|
||||
- [MISP Training materials](http://www.circle.lu/services/misp-training-materials/)
|
||||
- [MISP Tutorials](https://www.youtube.com/playlist?list=PLhSWiKucshm6Y01mAwBaF-mAPLuYKNrcc)
|
||||
- [MISP Summit 2016 playlist](https://www.youtube.com/playlist?list=PLCxOaebc_2yO6zBSAqfJtMaZh97ue_MLR)
|
||||
|
@ -46,7 +46,7 @@ MISP is mentioned occasionally in the press. This list is not comprehensive, but
|
|||
|
||||
|
||||
# Research
|
||||
- [MISP research projects](https://www.misp-project.org/research-projects/)
|
||||
- [MISP research projects](/research-projects/)
|
||||
- [MISP - The Design and Implementation of a Collaborative Threat Intelligence Sharing Platform](https://www.researchgate.net/publication/309413369_MISP_-The_Design_and_Implementation_of_a_Collaborative_Threat_Intelligence_Sharing_Platform)
|
||||
- [Taxonomy driven indicator scoring in MISP threat intelligence platforms](https://arxiv.org/abs/1902.03914)
|
||||
|
||||
|
|
|
@ -7,8 +7,8 @@ toc: true
|
|||
|
||||
# Help, Support, and Forums
|
||||
|
||||
Help and support for MISP is available from the [documentation](https://www.circl.lu/doc/misp/), [GitHub issues](https://github.com/MISP/MISP/issues), and [Gitter rooms](https://gitter.im/orgs/MISP/rooms) which are explained below.
|
||||
MISP Project [offers paid support services](https://www.misp-project.org/professional-services).
|
||||
Help and support for MISP is available from the [documentation](/documentation), [GitHub issues](https://github.com/MISP/MISP/issues), and [Gitter rooms](https://gitter.im/orgs/MISP/rooms) which are explained below.
|
||||
The MISP Project [offers paid support services](/professional-services).
|
||||
|
||||
If you’re looking for known issues or would like to file a bug report, please see the [issue tracker](https://github.com/MISP/MISP/issues).
|
||||
These issues are constantly being updated and may contain workarounds for problems that you’re experiencing, so it’s worth searching the issue tracker as a first step.
|
||||
|
@ -87,4 +87,12 @@ MISP Project has a presence on [Twitter (@MISPProject)](https://twitter.com/MISP
|
|||
Generally speaking, this is not intended to be a primary support venue.
|
||||
(Those would be [MISP/Support Gitter room]() and the issue tracker.)
|
||||
Rather, these are primarily intended to be a way to more widely disseminate news related to MISP.
|
||||
If you use Twitter, you may find it convenient to follow the MISP Project there as a way of receiving MISP news.
|
||||
If you use Twitter, you may find it convenient to follow the MISP Project there as a way of receiving MISP
|
||||
|
||||
## Email
|
||||
|
||||
Please use the previously mentioned channels if you need technical support.
|
||||
|
||||
If you have any other enquiries or are willing to contribute or support the project, don't hesitate to contact the team at [info@misp-project.org](mailto:info@misp-project.org).
|
||||
|
||||
|
||||
|
|
Loading…
Reference in New Issue