diff --git a/objects.html b/objects.html index cc39caf..88ae11a 100755 --- a/objects.html +++ b/objects.html @@ -463,6 +463,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
last-seen
-datetime
sensor
text
When the leak has been accessible or seen for the last time.
+The AIL sensor uuid where the leak was processed and analysed.
+
type
duplicate
text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
+Duplicate of the existing leaks.
++
duplicate_number
counter
Number of known duplicates.
@@ -594,36 +605,6 @@ ail-leak is a MISP object available in JSON format at
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
--
duplicate_number
counter
Number of known duplicates.
--
sensor
text
The AIL sensor uuid where the leak was processed and analysed.
--
text
text
duplicate
text
Duplicate of the existing leaks.
--
original-date
datetime
last-seen
datetime
When the leak has been accessible or seen for the last time.
++
origin
text
type
text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
++
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
++
permission
-text
comment
comment
Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
+Comment about the set of android permission(s)
comment
comment
permission
text
Comment about the set of android permission(s)
+Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
@@ -760,36 +761,6 @@ annotation is a MISP object available in JSON format at
type
text
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
--
ref
link
Reference(s) to the annotation
--
format
text
Format of the annotation ['text', 'markdown', 'asciidoctor', 'MultiMarkdown', 'GFM', 'pandoc', 'Fountain', 'CommonWork', 'kramdown-rfc2629', 'rfc7328', 'Extra']
--
text
text
format
text
Format of the annotation ['text', 'markdown', 'asciidoctor', 'MultiMarkdown', 'GFM', 'pandoc', 'Fountain', 'CommonWork', 'kramdown-rfc2629', 'rfc7328', 'Extra']
++
modification-date
datetime
ref
link
Reference(s) to the annotation
++
type
text
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
++
export
-text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
mp-export
text
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
--
last-seen
datetime
Last time the ASN was seen
--
subnet-announced
ip-src
Subnet announced
--
first-seen
datetime
asn
AS
description
text
Autonomous System Number
+Description of the autonomous system
++
export
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
@@ -928,10 +899,30 @@ asn is a MISP object available in JSON format at
mp-import
last-seen
datetime
Last time the ASN was seen
++
mp-export
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
asn
AS
Autonomous System Number
@@ -948,10 +939,20 @@ asn is a MISP object available in JSON format at
description
mp-import
text
Description of the autonomous system
+The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
subnet-announced
ip-src
Subnet announced
@@ -1016,20 +1017,20 @@ av-signature is a MISP object available in JSON format at
text
text
datetime
datetime
Free text value to attach to the file
+Datetime
datetime
datetime
text
text
Datetime
+Free text value to attach to the file
@@ -1074,6 +1075,26 @@ coin-address is a MISP object available in JSON format at
first-seen
datetime
First time this payment destination address has been seen
++
text
text
Free text value
++
symbol
text
first-seen
datetime
First time this payment destination address has been seen
--
text
text
Free text value
--
type
+cookie-name
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
--
cookie
cookie
Full cookie
--
cookie-value
text
Value of the cookie (if splitted)
+Name of the cookie (if splitted)
@@ -1202,10 +1183,30 @@ cookie is a MISP object available in JSON format at
cookie-name
cookie
cookie
Full cookie
++
type
text
Name of the cookie (if splitted)
+Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
++
cookie-value
text
Value of the cookie (if splitted)
@@ -1250,13 +1251,13 @@ credential is a MISP object available in JSON format at
type
text
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
+A description of the credential(s)
+
password
-text
Password
--
format
text
text
text
A description of the credential(s)
--
notification
text
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
++
password
text
Password
++
card-security-code
-text
Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
--
name
text
issued
datetime
Initial date of validity or issued date.
--
comment
comment
A description of the card.
--
version
text
cc-number
cc-number
card-security-code
text
credit-card number as encoded on the card.
+Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
++
issued
datetime
Initial date of validity or issued date.
cc-number
cc-number
credit-card number as encoded on the card.
++
comment
comment
A description of the card.
++
src-port
-port
text
text
Port originating the attack
+Description of the DDoS
-
domain-dst
domain
Destination domain (victim)
--
ip-dst
ip-dst
Destination IP (victim)
-+
total-bps
-counter
src-port
port
Bits per second
+Port originating the attack
text
text
Description of the DDoS
--
total-pps
counter
domain-dst
domain
Destination domain (victim)
++
total-bps
counter
Bits per second
++
protocol
text
ip-dst
ip-dst
Destination IP (victim)
++
ip-src
ip-src
Origin-Host
Origin-Realm
text
Origin-Host.
+Origin-Realm.
first-seen
datetime
text
text
When the attack has been seen for the first time.
+A description of the attack seen.
++
IdrFlags
text
IDR-Flags.
@@ -1654,20 +1665,30 @@ diameter-attack is a MISP object available in JSON format at
text
SessionId
text
A description of the attack seen.
+Session-ID.
++
first-seen
datetime
When the attack has been seen for the first time.
Destination-Host
Origin-Host
text
Destination-Host.
+Origin-Host.
@@ -1684,6 +1705,16 @@ diameter-attack is a MISP object available in JSON format at
Destination-Host
text
Destination-Host.
++
Destination-Realm
text
IdrFlags
text
IDR-Flags.
--
SessionId
text
Session-ID.
--
Origin-Realm
text
Origin-Realm.
--
category
text
ip
ip-dst
IP Address
--
domain
domain
Domain name
--
text
text
first-seen
datetime
First time the tuple has been seen
++
last-seen
datetime
first-seen
datetime
domain
domain
First time the tuple has been seen
+Domain name
+
+
ip
ip-dst
IP Address
+
number-sections
+counter
Number of sections
++
text
text
Free text value to attach to the ELF
++
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
++
arch
text
number-sections
counter
Number of sections
--
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
--
entrypoint-address
text
text
text
Free text value to attach to the ELF
--
name
+text
Name of the section
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha1
sha1
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
md5
md5
[Insecure] MD5 hash (128 bits)
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
++
entropy
float
Entropy of the whole section
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
text
text
Free text value to attach to the section
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
flag
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
++
type
text
entropy
float
Entropy of the whole section
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
ssdeep
ssdeep
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
name
text
Name of the section
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
flag
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
--
text
text
Free text value to attach to the section
--
thread-index
-email-thread-index
to-display-name
email-dst-display-name
Identifies a particular conversation thread
+Display name of the receiver
to-display-name
email-dst-display-name
attachment
email-attachment
Display name of the receiver
+Attachment
++
cc
email-dst
Carbon copy
++
header
email-header
Full headers
++
screenshot
attachment
Screenshot of email
++
return-path
text
Message return path
++
message-id
email-message-id
Message ID
++
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
@@ -2186,66 +2247,6 @@ email is a MISP object available in JSON format at
return-path
text
Message return path
--
send-date
datetime
Date the email has been sent
--
screenshot
attachment
Screenshot of email
--
from-display-name
email-src-display-name
Display name of the sender
--
message-id
email-message-id
Message ID
--
cc
email-dst
Carbon copy
--
subject
email-subject
x-mailer
email-x-mailer
thread-index
email-thread-index
X-Mailer generally tells the program that was used to draft and send the original email
+Identifies a particular conversation thread
@@ -2276,23 +2277,23 @@ email is a MISP object available in JSON format at
attachment
email-attachment
from-display-name
email-src-display-name
Attachment
+Display name of the sender
header
email-header
send-date
datetime
Full headers
+Date the email has been sent
+
authentihash
+authentihash
Authenticode executable signature hash
++
sha1
sha1
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
entropy
float
Entropy of the whole file
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
--
filename
filename
authentihash
authentihash
Authenticode executable signature hash
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
mimetype
text
Mime type
--
sha512/224
sha512/224
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
pattern-in-file
-pattern-in-file
certificate
x509-fingerprint-sha1
Pattern that can be found in the file
+Certificate value if the binary is signed with another authentication scheme than authenticode
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
--
sha224
sha224
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
malware-sample
-malware-sample
size-in-bytes
size-in-bytes
The file itself (binary)
+Size of the file, in bytes
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
@@ -2534,6 +2455,56 @@ file is a MISP object available in JSON format at
entropy
float
Entropy of the whole file
++
mimetype
text
Mime type
++
pattern-in-file
pattern-in-file
Pattern that can be found in the file
++
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
tlsh
tlsh
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
malware-sample
malware-sample
The file itself (binary)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
first-seen
+datetime
When the location was seen for the first time.
++
text
text
A generic description of the location.
++
longitude
float
last-seen
datetime
altitude
float
When the location was seen for the last time.
+The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
+
text
-text
last-seen
datetime
A generic description of the location.
+When the location was seen for the last time.
city
text
City.
--
country
text
altitude
float
city
text
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
+City.
first-seen
datetime
When the location was seen for the first time.
--
GtpVersion
+text
text
GTP version ['0', '1', '2']
+A description of the GTP attack.
first-seen
datetime
GtpServingNetwork
text
When the attack has been seen for the first time.
+GTP Serving Network.
@@ -2740,10 +2741,10 @@ gtp-attack is a MISP object available in JSON format at
PortDest
GtpMessageType
text
Destination port.
+GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
@@ -2760,10 +2761,40 @@ gtp-attack is a MISP object available in JSON format at
GtpServingNetwork
first-seen
datetime
When the attack has been seen for the first time.
++
PortDest
text
GTP Serving Network.
+Destination port.
++
ipSrc
ip-src
IP source address.
++
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
@@ -2790,10 +2821,10 @@ gtp-attack is a MISP object available in JSON format at
GtpInterface
GtpVersion
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
+GTP version ['0', '1', '2']
ipSrc
ip-src
IP source address.
--
text
text
A description of the GTP attack.
--
GtpMessageType
text
GTP defines a set of messages between two associated GSNs or an SGSN and an RNC. Message type is described as a decimal value.
--
uri
-uri
referer
referer
Request URI
--
proxy-password
text
HTTP Proxy Password
--
host
hostname
The domain name of the server
--
url
url
Full HTTP Request URL
--
text
text
HTTP Request comment
--
user-agent
user-agent
The user agent string of the user agent
--
content-type
other
The MIME type of the body of the request
+This is the address of the previous web page from which a link to the currently requested page was followed
@@ -2958,10 +2899,20 @@ http-request is a MISP object available in JSON format at
referer
referer
url
url
This is the address of the previous web page from which a link to the currently requested page was followed
+Full HTTP Request URL
++
host
hostname
The domain name of the server
@@ -2978,10 +2929,10 @@ http-request is a MISP object available in JSON format at
cookie
text
user-agent
user-agent
An HTTP cookie previously sent by the server with Set-Cookie
+The user agent string of the user agent
@@ -2998,6 +2949,26 @@ http-request is a MISP object available in JSON format at
text
text
HTTP Request comment
++
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
++
proxy-user
text
proxy-password
text
HTTP Proxy Password
++
content-type
other
The MIME type of the body of the request
++
uri
uri
Request URI
++
src-port
-port
text
text
Source port
--
last-seen
datetime
Last time the tuple has been seen
+Description of the tuple
@@ -3076,6 +3067,16 @@ ip-port is a MISP object available in JSON format at
src-port
port
Source port
++
ip
ip-dst
text
text
last-seen
datetime
Description of the tuple
+Last time the tuple has been seen
@@ -3144,6 +3145,26 @@ ja3 is a MISP object available in JSON format at
first-seen
datetime
First seen of the SSL/TLS handshake
++
description
text
Type of detected software ie software, malware
++
last-seen
datetime
description
text
ip-src
ip-src
Type of detected software ie software, malware
+Source IP Address
ip-src
ip-src
Source IP Address
--
first-seen
datetime
First seen of the SSL/TLS handshake
--
number-sections
+counter
Number of sections
++
name
text
number-sections
counter
Number of sections
--
entrypoint-address
text
sha1
sha1
name
text
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
entropy
float
Entropy of the whole section
+Name of the section
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
sha512
sha512
sha384
sha384
sha1
sha1
Secure Hash Algorithm 2 (384 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
sha512/224
sha512/224
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
name
-text
Name of the section
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
sha224
sha224
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
size-in-bytes
+size-in-bytes
Size of the section, in bytes
++
entropy
float
Entropy of the whole section
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
text
text
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
type
+username
text
Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
+Username who posted the microblog post
+
+
post
text
Raw post
++
username-quoted
text
Username who are quoted into the microblog post
++
modification-date
datetime
Last update of the microblog post
+
username
-text
creation-date
datetime
Username who posted the microblog post
+Initial creation of the microblog post
type
text
Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
++
link
url
Object to describe mutual exclusion locks (mutex) as seen in memory or computer program.
+creation-date |
-datetime |
-
- Initial creation of the microblog post - |
-
- - |
++ + | ++mutex is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + |
username-quoted |
+Object attribute | +MISP attribute type | +Description | +Disable correlation | +||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
name |
text |
- Username who are quoted into the microblog post +name of the mutex |
|
|||||||||
post |
+description |
text |
- Raw post +Description |
|
||||||||
modification-date |
-datetime |
+operating-system |
+text |
- Last update of the microblog post +Operating system where the mutex has been seen ['Windows', 'Unix'] |
@@ -3626,10 +3695,10 @@ netflow is a MISP object available in JSON format at byte-count |
+flow-count |
counter |
- Bytes counted in this flow +Flows counted in this flow |
@@ -3646,36 +3715,6 @@ netflow is a MISP object available in JSON format at icmp-type |
-text |
-
- ICMP type of the flow (if the traffic is ICMP) - |
-
- - |
-
ip-dst |
-ip-dst |
-
- IP address destination of the netflow - |
-
- - |
-|||||||||
ip_version |
-counter |
-
- IP version of this flow - |
-
- - |
-|||||||||
src-as |
AS |
@@ -3686,36 +3725,16 @@ netflow is a MISP object available in JSON format at packet-count |
-counter |
+icmp-type |
+text |
- Packets counted in this flow +ICMP type of the flow (if the traffic is ICMP) |
|
|||||
ip-src |
-ip-src |
-
- IP address source of the netflow - |
-
- - |
-|||||||||
dst-port |
-port |
-
- Destination port of the netflow - |
-
- - |
-|||||||||
protocol |
text |
@@ -3726,46 +3745,6 @@ netflow is a MISP object available in JSON format at direction |
-text |
-
- Direction of this flow ['Ingress', 'Egress'] - |
-
- - |
-|||||||
first-packet-seen |
-datetime |
-
- First packet seen in this flow - |
-
- - |
-|||||||||
ip-protocol-number |
-size-in-bytes |
-
- IP protocol number of this flow - |
-
- - |
-|||||||||
flow-count |
-counter |
-
- Flows counted in this flow - |
-
- - |
-|||||||||
last-packet-seen |
datetime |
@@ -3786,6 +3765,26 @@ netflow is a MISP object available in JSON format at packet-count |
+counter |
+
+ Packets counted in this flow + |
+
+ + |
+|||||||
direction |
+text |
+
+ Direction of this flow ['Ingress', 'Egress'] + |
+
+ + |
+|||||||||
tcp-flags |
text |
|||||||||||
ip-protocol-number |
+size-in-bytes |
+
+ IP protocol number of this flow + |
+
+ + |
+|||||||||
first-packet-seen |
+datetime |
+
+ First packet seen in this flow + |
+
+ + |
+|||||||||
dst-port |
+port |
+
+ Destination port of the netflow + |
+
+ + |
+|||||||||
ip-dst |
+ip-dst |
+
+ IP address destination of the netflow + |
+
+ + |
+|||||||||
ip-src |
+ip-src |
+
+ IP address source of the netflow + |
+
+ + |
+|||||||||
byte-count |
+counter |
+
+ Bytes counted in this flow + |
+
+ + |
+|||||||||
ip_version |
+counter |
+
+ IP version of this flow + |
+
+ + |
+
zone_time_first
-datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
time_first
datetime
count
counter
zone_time_first
datetime
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
+First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
@@ -3884,10 +3943,10 @@ passive-dns is a MISP object available in JSON format at
text
text
zone_time_last
datetime
+
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
@@ -3914,10 +3973,10 @@ passive-dns is a MISP object available in JSON format at
zone_time_last
datetime
text
text
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
+
@@ -3944,6 +4003,16 @@ passive-dns is a MISP object available in JSON format at
count
counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
++
origin
text
last-seen
first-seen
datetime
When the paste has been accessible or seen for the last time.
+When the paste has been accessible or seen for the first time.
@@ -4012,13 +4081,13 @@ paste is a MISP object available in JSON format at
first-seen
datetime
title
text
When the paste has been accessible or seen for the first time.
+Title of the paste or post.
+
title
-text
Title of the paste or post.
--
origin
text
last-seen
datetime
When the paste has been accessible or seen for the last time.
++
product-name
-text
number-sections
counter
ProductName in the resources
+Number of sections
@@ -4110,60 +4179,10 @@ pe is a MISP object available in JSON format at
internal-filename
filename
InternalFilename in the resources
--
number-sections
counter
Number of sections
--
imphash
imphash
Hash (md5) calculated from the import table
--
entrypoint-address
product-version
text
Address of the entry point
--
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
--
text
text
Free text value to attach to the PE
+ProductVersion in the resources
@@ -4180,6 +4199,36 @@ pe is a MISP object available in JSON format at
imphash
imphash
Hash (md5) calculated from the import table
++
original-filename
filename
OriginalFilename in the resources
++
text
text
Free text value to attach to the PE
++
entrypoint-section-at-position
text
impfuzzy
impfuzzy
compilation-timestamp
datetime
Fuzzy Hash (ssdeep) calculated from the import table
+Compilation timestamp defined in the PE header
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
--
company-name
text
CompanyName in the resources
--
original-filename
internal-filename
filename
OriginalFilename in the resources
+InternalFilename in the resources
@@ -4240,10 +4269,60 @@ pe is a MISP object available in JSON format at
product-version
lang-id
text
ProductVersion in the resources
+Lang ID in the resources
++
product-name
text
ProductName in the resources
++
company-name
text
CompanyName in the resources
++
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
++
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
++
entrypoint-address
text
Address of the entry point
lang-id
text
Lang ID in the resources
--
sha1
-sha1
name
text
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
entropy
float
Entropy of the whole section
+Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
sha512
sha512
sha384
sha384
sha1
sha1
Secure Hash Algorithm 2 (384 bits)
+[Insecure] Secure Hash Algorithm 1 (160 bits)
characteristic
text
Characteristic of the section ['read', 'write', 'executable']
--
sha512/224
sha512/224
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
name
-text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
sha224
sha224
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
size-in-bytes
+size-in-bytes
Size of the section, in bytes
++
entropy
float
Entropy of the whole section
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
text
text
characteristic
text
Characteristic of the section ['read', 'write', 'executable']
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
++
passport-country
-passport-country
place-of-birth
place-of-birth
The country in which the passport was issued.
+Place of birth of a natural person.
+
+
alias
text
Alias name or known as.
+
text
-text
A description of the person or identity.
--
last-name
last-name
passport-expiration
passport-expiration
nationality
nationality
The expiration date of a passport.
+The nationality of a natural person.
++
text
text
A description of the person or identity.
++
mothers-name
text
Mother name, father, second name or other names following country’s regulation.
++
title
text
Title of the natural person such as Dr. or equivalent.
++
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
@@ -4556,50 +4665,50 @@ person is a MISP object available in JSON format at
middle-name
middle-name
Middle name of a natural person
--
nationality
nationality
The nationality of a natural person.
--
place-of-birth
place-of-birth
Place of birth of a natural person.
--
first-name
first-name
First name of a natural person.
+
social-security-number
text
Social security number
+
redress-number
redress-number
passport-expiration
passport-expiration
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
+The expiration date of a passport.
++
passport-country
passport-country
The country in which the passport was issued.
++
middle-name
middle-name
Middle name of a natural person.
@@ -4654,46 +4763,16 @@ phone is a MISP object available in JSON format at
msisdn
imei
text
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
+International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
last-seen
datetime
When the phone has been accessible or seen for the last time.
--
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
--
first-seen
datetime
When the phone has been accessible or seen for the first time.
--
gummei
text
imei
guti
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
+Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
imsi
text
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
+A description of the phone.
++
msisdn
text
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
@@ -4734,10 +4823,30 @@ phone is a MISP object available in JSON format at
text
last-seen
datetime
When the phone has been accessible or seen for the last time.
++
imsi
text
A description of the phone.
+A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
++
first-seen
datetime
When the phone has been accessible or seen for the first time.
@@ -4782,20 +4891,10 @@ r2graphity is a MISP object available in JSON format at
local-references
callback-average
counter
Amount of API calls inside a code section
--
r2-commit-version
text
Radare2 commit ID used to generate this object
+Average size of a callback
@@ -4812,160 +4911,10 @@ r2graphity is a MISP object available in JSON format at
gml
attachment
Graph export in G>raph Modelling Language format
--
referenced-strings
local-references
counter
Amount of referenced strings
--
total-api
counter
Total amount of API calls
--
not-referenced-strings
counter
Amount of not referenced strings
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
total-functions
counter
Total amount of functions in the file.
--
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
--
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
create-thread
counter
Amount of calls to CreateThread
--
callbacks
counter
Amount of callbacks (functions started as thread)
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
+Amount of API calls inside a code section
@@ -4982,20 +4931,180 @@ r2graphity is a MISP object available in JSON format at
callback-average
counter
text
text
Average size of a callback
+Description of the r2graphity object
text
create-thread
counter
Amount of calls to CreateThread
++
get-proc-address
counter
Amount of calls to GetProcAddress
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
++
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
++
total-functions
counter
Total amount of functions in the file.
++
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
++
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
++
r2-commit-version
text
Description of the r2graphity object
+Radare2 commit ID used to generate this object
++
not-referenced-strings
counter
Amount of not referenced strings
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
referenced-strings
counter
Amount of referenced strings
++
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
++
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
++
gml
attachment
Graph export in G>raph Modelling Language format
++
total-api
counter
Total amount of API calls
++
callbacks
counter
Amount of callbacks (functions started as thread)
++
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
@@ -5040,13 +5149,13 @@ regexp is a MISP object available in JSON format at
type
regexp-type
text
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
+Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
+
regexp-type
+type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
+Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
+
data
-text
Data stored in the registry key
--
root-keys
text
Root key of the Windows registry (extracted from the key) ['HKCC', 'HKCR', 'HKCU', 'HKDD', 'HKEY_CLASSES_ROOT', 'HKEY_CURRENT_CONFIG', 'HKEY_CURRENT_USER', 'HKEY_DYN_DATA', 'HKEY_LOCAL_MACHINE', 'HKEY_PERFORMANCE_DATA', 'HKEY_USERS', 'HKLM', 'HKPD', 'HKU']
--
name
text
key
regkey
Full key path
--
hive
text
Hive used to store the registry key (file on disk)
--
data-type
text
data
text
Data stored in the registry key
++
key
regkey
Full key path
++
root-keys
text
Root key of the Windows registry (extracted from the key) ['HKCC', 'HKCR', 'HKCU', 'HKDD', 'HKEY_CLASSES_ROOT', 'HKEY_CURRENT_CONFIG', 'HKEY_CURRENT_USER', 'HKEY_DYN_DATA', 'HKEY_LOCAL_MACHINE', 'HKEY_PERFORMANCE_DATA', 'HKEY_USERS', 'HKLM', 'HKPD', 'HKU']
++
hive
text
Hive used to store the registry key (file on disk)
++
constituency
+ticket-number
text
Constituency of the RTIR ticket
--
status
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
--
subject
text
Subject of the RTIR ticket
--
ip
ip-dst
IPs automatically extracted from the RTIR ticket
+ticket-number of the RTIR ticket
@@ -5334,20 +5413,50 @@ rtir is a MISP object available in JSON format at
classification
subject
text
Classification of the RTIR ticket
+Subject of the RTIR ticket
ticket-number
constituency
text
ticket-number of the RTIR ticket
+Constituency of the RTIR ticket
++
ip
ip-dst
IPs automatically extracted from the RTIR ticket
++
status
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
++
classification
text
Classification of the RTIR ticket
@@ -5392,36 +5501,6 @@ sandbox-report is a MISP object available in JSON format at
on-premise-sandbox
text
The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
--
results
text
Freetext result values
--
raw-report
text
Raw report from sandbox
--
sandbox-type
text
saas-sandbox
text
A non-on-premise sandbox, also results are not publicly available ['forticloud-sandbox', 'joe-sandbox-cloud', 'symantec-cas-cloud']
--
score
text
Score
--
permalink
link
score
text
Score
++
web-sandbox
text
results
text
Freetext result values
++
on-premise-sandbox
text
The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise']
++
saas-sandbox
text
A non-on-premise sandbox, also results are not publicly available ['forticloud-sandbox', 'joe-sandbox-cloud', 'symantec-cas-cloud']
++
raw-report
text
Raw report from sandbox
++
SccpCdGT
+text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
++
Category
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
++
MapMscGT
text
MAP MSC GT. Phone number.
++
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
++
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
++
MapApplicationContext
text
MAP application context in OID format.
++
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
++
MapMsisdn
text
MAP MSISDN. Phone number.
++
text
text
A description of the attack seen via SS7 logging.
++
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
++
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
++
MapUssdContent
text
MAP USSD Content.
++
MapVersion
text
Map version. ['1', '2', '3']
++
MapSmsTP-DCS
text
MAP SMS TP-DCS.
++
MapUssdCoding
text
MAP USSD Content.
++
MapGmlc
text
MAP GMLC. Phone number.
++
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
++
MapSmsTP-PID
text
MAP SMS TP-PID.
++
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
++
MapSmscGT
text
MAP SMSC. Phone number.
++
MapSmsTypeNumber
text
MAP SMS TypeNumber.
++
first-seen
datetime
When the attack has been seen for the first time.
++
MapVlrGT
text
MapMscGT
MapGsmscfGT
text
MAP MSC GT. Phone number.
--
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
--
Category
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
--
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
--
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
MapUssdCoding
text
MAP USSD Content.
--
MapMsisdn
text
MAP MSISDN. Phone number.
+MAP GSMSCF GT. Phone number.
MapUssdContent
text
MAP USSD Content.
--
MapGmlc
text
MAP GMLC. Phone number.
--
MapGsmscfGT
text
MAP GSMSCF GT. Phone number.
--
MapVersion
text
Map version. ['1', '2', '3']
--
SccpCdGT
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
--
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
--
first-seen
datetime
When the attack has been seen for the first time.
--
MapSmsTP-DCS
text
MAP SMS TP-DCS.
--
text
text
A description of the attack seen via SS7 logging.
--
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
--
MapSmscGT
text
MAP SMSC. Phone number.
--
MapApplicationContext
text
MAP application context in OID format.
--
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
--
MapSmsTypeNumber
text
MAP SMS TypeNumber.
--
MapSmsTP-PID
text
MAP SMS TP-PID.
--
version
+description
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
address
ip-src
IP address of the Tor node seen.
--
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
+Tor node description.
@@ -5906,6 +5995,56 @@ tor-node is a MISP object available in JSON format at
nickname
text
router’s nickname.
++
address
ip-src
IP address of the Tor node seen.
++
flags
text
list of flag associated with the node.
++
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
++
fingerprint
text
router’s fingerprint.
++
text
text
description
version
text
Tor node description.
+parsed version of tor, this is None if the relay’s using a new versioning scheme.
++
document
text
Raw document from the consensus.
nickname
text
router’s nickname.
--
fingerprint
text
router’s fingerprint.
--
flags
text
list of flag associated with the node.
--
document
text
Raw document from the consensus.
--
tld
-text
Top-Level Domain
--
query_string
text
first-seen
datetime
First time this URL has been seen
--
url
url
Full URL
--
credential
text
Credential (username, password)
--
subdomain
text
text
text
host
hostname
Description of the URL
+Full hostname
++
url
url
Full URL
@@ -6104,6 +6183,56 @@ url is a MISP object available in JSON format at
credential
text
Credential (username, password)
++
text
text
Description of the URL
++
first-seen
datetime
First time this URL has been seen
++
resource_path
text
Path (between hostname:port and query)
++
domain
domain
Full domain
++
scheme
text
domain
domain
tld
text
Full domain
+Top-Level Domain
++
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
@@ -6134,26 +6273,6 @@ url is a MISP object available in JSON format at
host
hostname
Full hostname
--
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
--
domain_without_tld
text
resource_path
text
Path (between hostname:port and query)
--
node
-target-machine
name
target-org
Name(s) of node that was targeted.
+The name of the department(s) or organisation(s) targeted.
++
description
text
Description of the victim
++
classification
text
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
++
sectors
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
@@ -6232,10 +6371,10 @@ victim is a MISP object available in JSON format at
name
target-org
node
target-machine
The name of the department(s) or organisation(s) targeted.
+Name(s) of node that was targeted.
@@ -6252,13 +6391,13 @@ victim is a MISP object available in JSON format at
classification
text
external
target-external
The type of entity being targeted. ['individual', 'group', 'organization', 'class', 'unknown']
+External target organisations affected by this attack.
+
sectors
-text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
--
roles
text
description
text
Description of the victim
--
external
target-external
External target organisations affected by this attack.
--
last-submission
+first-submission
datetime
Last Submission
+First Submission
@@ -6390,10 +6499,10 @@ virustotal-report is a MISP object available in JSON format at
first-submission
last-submission
datetime
First Submission
+Last Submission
@@ -6448,13 +6557,43 @@ vulnerability is a MISP object available in JSON format at
modified
datetime
text
text
Last modification date
+Description of the vulnerability
+
+
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
++
summary
text
Summary of the vulnerability
++
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely). The id is not required as the object itself has an UUID and the CVE id can updated later.
+
created
+datetime
First time when the vulnerability was discovered
++
modified
datetime
Last modification date
++
references
link
summary
text
Summary of the vulnerability
--
text
text
Description of the vulnerability
--
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely). The id is not required as the object itself has an UUID and the CVE id can updated later.
--
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
--
created
datetime
First time when the vulnerability was discovered
--
expiration-date
-datetime
text
text
Expiration of the whois entry
+Full whois entry
registrant-email
whois-registrant-email
Registrant email address
--
registrar
whois-registrar
Registrar of the whois entry
--
creation-date
datetime
domain
domain
expiration-date
datetime
Domain of the whois entry
+Expiration of the whois entry
+
registrant-phone
whois-registrant-phone
modification-date
datetime
Registrant phone number
--
text
text
Full whois entry
+Last update of the whois entry
@@ -6666,6 +6745,46 @@ whois is a MISP object available in JSON format at
domain
domain
Domain of the whois entry
++
registrant-email
whois-registrant-email
Registrant email address
++
registrar
whois-registrar
Registrar of the whois entry
++
registrant-phone
whois-registrant-phone
Registrant phone number
++
nameserver
hostname
modification-date
datetime
Last update of the whois entry
--
serial-number
+pubkey-info-modulus
text
Serial number of the certificate
+Modulus of the public key
@@ -6744,6 +6853,66 @@ x509 is a MISP object available in JSON format at
text
text
Free text description of hte certificate
++
version
text
Version of the certificate
++
serial-number
text
Serial number of the certificate
++
pubkey-info-size
text
Length of the public key (in bits)
++
pubkey-info-exponent
text
Exponent of the public key
++
issuer
text
Issuer of the certificate
++
pubkey-info-algorithm
text
pubkey-info-modulus
text
x509-fingerprint-sha256
x509-fingerprint-sha256
Modulus of the public key
+Secure Hash Algorithm 2 (256 bits)
x509-fingerprint-md5
x509-fingerprint-md5
subject
text
[Insecure] MD5 hash (128 bits)
+Subject of the certificate
++
validity-not-after
datetime
Certificate invalid after that date
@@ -6794,80 +6973,10 @@ x509 is a MISP object available in JSON format at
pubkey-info-size
text
x509-fingerprint-md5
x509-fingerprint-md5
Length of the public key (in bits)
--
validity-not-after
datetime
Certificate invalid after that date
--
version
text
Version of the certificate
--
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
--
issuer
text
Issuer of the certificate
--
subject
text
Subject of the certificate
--
pubkey-info-exponent
text
Exponent of the public key
--
text
text
Free text description of hte certificate
+[Insecure] MD5 hash (128 bits)
@@ -6912,13 +7021,13 @@ yabin is a MISP object available in JSON format at
whitelist
comment
yara
yara
Whitelist name used to generate the rules.
+Yara rule generated from -y.
+
yara
-yara
Yara rule generated from -y.
--
yara-hunt
yara
whitelist
comment
Whitelist name used to generate the rules.
++