diff --git a/objects.html b/objects.html index 2483a01..49f1225 100755 --- a/objects.html +++ b/objects.html @@ -478,7 +478,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
MISP MISP objects to be used in MISP (2.4.80 (TBC)) system and can be used by other information sharing tool. MISP objects are in addition to MISP attributes to allow advanced combinations of attributes. The creation of these objects and their associated attributes are based on real cyber security use-cases and existing practices in information sharing.
+MISP MISP objects to be used in MISP (2.4.80) system and can be used by other information sharing tool. MISP objects are in addition to MISP attributes to allow advanced combinations of attributes. The creation of these objects and their associated attributes are based on real cyber security use-cases and existing practices in information sharing.
last-seen
+first-seen
datetime
@@ -537,6 +537,36 @@ ail-leak is a MISP object available in JSON format at
origin
url
+
+
original-date
datetime
+
+
text
text
+
+
type
text
origin
url
-
-
first-seen
last-seen
datetime
original-date
datetime
-
-
text
text
-
-
text
+text
+
+
cookie-value
text
type
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
++
cookie-name
text
text
text
-
-
cookie
cookie
type
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
--
version
+text
+
+
issued
datetime
card-security-code
text
comment
comment
version
+card-security-code
text
comment
comment
-
-
first-seen
+datetime
+
+
last-seen
datetime
+
+
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
++
ip-dst
ip-dst
+
+
text
text
+
+
total-bps
counter
+
+
src-port
port
+
+
ip-src
ip-src
last-seen
datetime
-
-
total-bps
counter
-
-
dst-port
port
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
--
first-seen
datetime
-
-
src-port
port
-
-
text
text
-
-
ip-dst
ip-dst
-
-
ip
-ip-dst
text
text
domain
+domain
+
+
last-seen
datetime
text
text
-
-
domain
domain
ip
ip-dst
entrypoint-address
+text
text
@@ -1057,16 +1057,6 @@ elf is a MISP object available in JSON format at
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
--
number-sections
counter
text
text
-
-
arch
text
os_abi
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
++
entrypoint-address
text
+
+
md5
-md5
-
-
sha224
sha224
-
-
size-in-bytes
size-in-bytes
sha512/256
sha512/256
+
+
type
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
++
sha512/224
sha512/224
+
+
text
text
sha256
sha256
+
+
sha512
sha512
+
+
sha224
sha224
+
+
ssdeep
ssdeep
+
+
md5
md5
+
+
flag
text
sha512
sha512
-
-
type
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
--
sha384
sha384
-
-
sha1
sha1
sha512/224
sha512/224
-
-
sha512/256
sha512/256
-
-
ssdeep
ssdeep
sha384
sha384
sha256
sha256
-
-
attachment
-email-attachment
-
-
message-id
email-message-id
-
-
thread-index
email-thread-index
-
-
from
email-src
-
-
from-display-name
email-src-display-name
-
-
to
email-dst
x-mailer
email-x-mailer
reply-to
email-reply-to
send-date
-datetime
-
-
subject
email-subject
header
email-header
-
-
mime-boundary
email-mime-boundary
header
email-header
+
+
thread-index
email-thread-index
+
+
x-mailer
email-x-mailer
+
+
to-display-name
email-dst-display-name
reply-to
email-reply-to
send-date
datetime
+
+
from
email-src
+
+
message-id
email-message-id
+
+
from-display-name
email-src-display-name
+
+
attachment
email-attachment
size-in-bytes
+size-in-bytes
+
+
sha512/256
sha512/256
+
+
filename
filename
sha512/224
sha512/224
+
+
pattern-in-file
pattern-in-file
md5
md5
tlsh
tlsh
sha224
-sha224
-
-
sha1
sha1
-
-
sha512/256
sha512/256
-
-
sha512
sha512
malware-sample
malware-sample
sha384
-sha384
-
-
size-in-bytes
size-in-bytes
-
-
authentihash
authentihash
-
-
sha512/224
sha512/224
-
-
entropy
float
sha256
sha256
+
+
sha512
sha512
+
+
sha224
sha224
+
+
ssdeep
ssdeep
malware-sample
malware-sample
md5
md5
+
+
sha1
sha1
+
+
sha384
sha384
tlsh
-tlsh
-
-
sha256
sha256
authentihash
authentihash
longitude
+altitude
float
+
text
text
+
region
city
text
@@ -1759,16 +1769,6 @@ geolocation is a MISP object available in JSON format at
city
text
-
-
first-seen
datetime
text
text
longitude
float
altitude
-float
region
text
uri
-uri
-
-
url
url
-
-
proxy-password
text
-
-
proxy-user
text
user-agent
user-agent
method
http-method
+
basicauth-user
text
text
+
referer
-referer
-
-
basicauth-password
text
-
-
cookie
text
-
-
content-type
other
text
basicauth-user
text
+
method
http-method
proxy-password
text
+
+
referer
referer
+
+
url
url
+
+
basicauth-password
text
+
+
user-agent
user-agent
+
+
uri
uri
+
+
cookie
text
+
src-port
-port
first-seen
datetime
dst-port
-port
-
-
first-seen
datetime
text
text
text
-text
src-port
port
+
+
dst-port
port
ip-src
-ip-src
ja3-fingerprint-md5
md5
ja3-fingerprint-md5
-md5
ip-src
ip-src
text
+text
+
+
type
text
Type of Mach-O ['BUNDLE', 'CORE', 'DSYM', 'DYLIB', 'DYLIB_STUB', 'DYLINKER', 'EXECUTE', 'FVMLIB', 'KEXT_BUNDLE', 'OBJECT', 'PRELOAD']
++
number-sections
counter
+
+
entrypoint-address
text
text
text
-
-
number-sections
counter
-
-
type
text
Type of Mach-O ['BUNDLE', 'CORE', 'DSYM', 'DYLIB', 'DYLIB_STUB', 'DYLINKER', 'EXECUTE', 'FVMLIB', 'KEXT_BUNDLE', 'OBJECT', 'PRELOAD']
--
md5
-md5
-
-
sha224
sha224
-
-
size-in-bytes
size-in-bytes
sha512/256
sha512/256
+
+
sha512/224
sha512/224
+
+
text
text
sha256
sha256
+
+
sha512
sha512
sha384
sha384
sha224
sha224
+
+
ssdeep
ssdeep
+
+
md5
md5
sha512/224
-sha512/224
-
-
sha512/256
sha512/256
-
-
ssdeep
ssdeep
sha384
sha384
sha256
sha256
-
-
zone_time_first
-datetime
-
-
time_last
datetime
time_first
text
text
+
+
zone_time_first
datetime
@@ -2507,17 +2507,7 @@ passive-dns is a MISP object available in JSON format at
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
--
rrname
origin
text
@@ -2537,26 +2527,6 @@ passive-dns is a MISP object available in JSON format at
origin
text
-
-
text
text
-
-
zone_time_last
datetime
time_first
datetime
+
+
sensor_id
text
+
+
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
++
bailiwick
text
sensor_id
rrname
text
@@ -2625,7 +2625,47 @@ pe is a MISP object available in JSON format at
original-filename
company-name
text
+
+
legal-copyright
text
+
+
number-sections
counter
+
+
impfuzzy
impfuzzy
+
+
internal-filename
filename
@@ -2635,6 +2675,26 @@ pe is a MISP object available in JSON format at
entrypoint-section-at-position
text
+
+
text
text
+
+
product-name
text
entrypoint-address
text
+
+
compilation-timestamp
datetime
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
--
entrypoint-section-at-position
product-version
text
@@ -2675,18 +2735,8 @@ pe is a MISP object available in JSON format at
internal-filename
filename
-
-
imphash
imphash
pehash
pehash
entrypoint-address
-text
imphash
imphash
+
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
+
number-sections
-counter
-
-
legal-copyright
text
-
-
pehash
pehash
original-filename
filename
product-version
text
-
-
text
text
-
-
impfuzzy
impfuzzy
-
-
company-name
text
-
-
characteristic
-text
Characteristic of the section ['read', 'write', 'executable']
--
md5
md5
-
-
sha224
sha224
-
-
size-in-bytes
size-in-bytes
sha512/256
sha512/256
+
+
sha512/224
sha512/224
+
+
text
text
characteristic
text
Characteristic of the section ['read', 'write', 'executable']
++
sha256
sha256
+
+
sha512
sha512
sha384
sha384
sha224
sha224
+
+
ssdeep
ssdeep
+
+
md5
md5
sha512/224
-sha512/224
-
-
sha512/256
sha512/256
-
-
ssdeep
ssdeep
sha384
sha384
sha256
sha256
-
-
passport-expiration
-passport-expiration
place-of-birth
place-of-birth
passport-number
-passport-number
first-name
first-name
+
+
passport-country
passport-country
+
+
text
text
+
+
redress-number
redress-number
+
+
nationality
nationality
redress-number
-redress-number
passport-expiration
passport-expiration
nationality
-nationality
-
-
last-name
last-name
first-name
first-name
passport-number
passport-number
passport-country
passport-country
-
-
place-of-birth
place-of-birth
-
-
text
text
-
-
msisdn
text
-
-
tmsi
text
-
guti
text
-
-
gummei
text
-
-
first-seen
datetime
-
text
-text
first-seen
datetime
msisdn
+text
+
+
imei
text
+
+
gummei
text
+
+
imsi
text
imei
tmsi
text
+
+
guti
text
@@ -3317,6 +3317,26 @@ r2graphity is a MISP object available in JSON format at
referenced-strings
counter
+
+
text
text
+
+
callback-largest
counter
gml
attachment
+
+
callback-average
counter
+
+
dangling-strings
counter
+
+
miss-api
counter
+
+
shortest-path-to-create-thread
counter
+
+
not-referenced-strings
counter
+
+
memory-allocations
counter
+
+
ratio-string
float
+
+
create-thread
counter
+
+
r2-commit-version
text
+
+
unknown-references
counter
+
+
callbacks
counter
+
+
local-references
counter
callbacks
total-api
counter
@@ -3367,96 +3507,6 @@ r2graphity is a MISP object available in JSON format at
r2-commit-version
text
-
-
create-thread
counter
-
-
text
text
-
-
shortest-path-to-create-thread
counter
-
-
memory-allocations
counter
-
-
gml
attachment
-
-
miss-api
counter
-
-
ratio-string
float
-
-
not-referenced-strings
counter
-
-
total-functions
counter
unknown-references
counter
-
-
callback-average
counter
-
-
ratio-functions
float
-
-
total-api
counter
-
-
dangling-strings
counter
-
-
refsglobalvar
counter
referenced-strings
counter
ratio-functions
float
regexp
+text
+
+
regexp-type
text
regexp
text
-
-
data
-reg-data
-
-
key
reg-key
hive
reg-hive
hive
-reg-hive
key
reg-key
data
+reg-data
+
+
name
reg-name
published
datetime
version_line
text
+
version_line
-text
-
-
description
text
-
-
fingerprint
text
-
-
flags
text
-
-
first-seen
datetime
-
-
last-seen
datetime
-
-
text
text
description
text
+
+
published
datetime
+
+
flags
text
+
+
first-seen
datetime
+
+
fingerprint
text
+
+
last-seen
datetime
+
+
last-seen
-datetime
tld
text
domain_without_tld
+fragment
text
@@ -3929,27 +3929,7 @@ url is a MISP object available in JSON format at
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
--
fragment
text
-
-
tld
text
@@ -3969,8 +3949,8 @@ url is a MISP object available in JSON format at
domain
domain
port
port
credential
+scheme
text
-
-
subdomain
text
+
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
@@ -4019,6 +3989,16 @@ url is a MISP object available in JSON format at
last-seen
datetime
+
+
url
url
text
subdomain
text
@@ -4039,8 +4019,28 @@ url is a MISP object available in JSON format at
port
port
domain
domain
+
+
domain_without_tld
text
+
+
credential
text
sectors
+roles
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial\xadservices', 'government\xadnational', 'government\xadregional', 'government\xadlocal', 'government\xadpublic\xadservices', 'healthcare', 'hospitality\xadleisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non\xadprofit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
+
@@ -4117,10 +4117,10 @@ victim is a MISP object available in JSON format at
roles
sectors
text
+
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial\xadservices', 'government\xadnational', 'government\xadregional', 'government\xadlocal', 'government\xadpublic\xadservices', 'healthcare', 'hospitality\xadleisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non\xadprofit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
@@ -4205,16 +4205,6 @@ vulnerability is a MISP object available in JSON format at
references
link
-
-
text
text
summary
text
references
link
summary
text
+
+
expiration-date
-datetime
-
-
creation-date
datetime
-
-
registrant-phone
whois-registrant-phone
modification-date
datetime
-
-
domain
domain
-
-
text
text
-
-
registrant-name
whois-registrant-name
registar
whois-registrar
expiration-date
datetime
+
+
modification-date
datetime
+
+
text
text
+
+
domain
domain
creation-date
datetime
+
+
registar
whois-registrar
+
+
x509-fingerprint-md5
-md5
-
-
pubkey-info-algorithm
text
-
-
version
text
-
-
pubkey-info-size
text
-
-
validity-not-after
datetime
-
-
issuer
text
-
-
pubkey-info-exponent
text
-
-
validity-not-before
datetime
-
-
raw-base64
subject
text
@@ -4521,7 +4441,17 @@ x509 is a MISP object available in JSON format at
subject
pubkey-info-size
text
+
+
text
text
@@ -4541,7 +4471,17 @@ x509 is a MISP object available in JSON format at
text
x509-fingerprint-sha1
sha1
+
+
pubkey-info-exponent
text
@@ -4561,8 +4501,68 @@ x509 is a MISP object available in JSON format at
x509-fingerprint-sha1
sha1
validity-not-after
datetime
+
+
pubkey-info-algorithm
text
+
+
x509-fingerprint-md5
md5
+
+
version
text
+
+
issuer
text
+
+
raw-base64
text
+
+
validity-not-before
datetime
version
-comment
yara
yara
+
comment
+version
comment
@@ -4649,13 +4649,13 @@ yabin is a MISP object available in JSON format at
yara
yara
comment
comment
+