Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
-
-
-
-
-
-
text
text
-
+
Raw text of the annotation
-
+
ref
link
-
+
Reference(s) to the annotation
-
-
-
-
-
-
creation-date
-
datetime
-
-
Initial creation of the annotation
-
-
+
format
text
-
+
Format of the annotation ['text', 'markdown', 'asciidoctor', 'MultiMarkdown', 'GFM', 'pandoc', 'Fountain', 'CommonWork', 'kramdown-rfc2629', 'rfc7328', 'Extra']
-
+
+
creation-date
+
datetime
+
+
Initial creation of the annotation
+
+
+
+
+
+
modification-date
datetime
-
+
Last update of the annotation
-
+
+
+
type
+
text
+
+
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
+
+
+
+
+
@@ -861,7 +868,7 @@ asn is a MISP object available in JSON format at
+
@@ -880,100 +887,100 @@ asn is a MISP object available in JSON format at
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
-
-
-
-
-
-
export
-
text
-
-
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
-
-
-
-
-
-
-
country
-
text
-
-
Country code of the main location of the autonomous system
-
-
-
-
-
-
-
mp-import
-
text
-
-
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
-
-
-
-
-
-
-
subnet-announced
-
ip-src
-
-
Subnet announced
-
-
-
-
-
-
-
description
-
text
-
-
Description of the autonomous system
-
-
+
first-seen
datetime
-
+
First time the ASN was seen
-
+
+
country
+
text
+
+
Country code of the main location of the autonomous system
+
+
+
+
+
+
+
subnet-announced
+
ip-src
+
+
Subnet announced
+
+
+
+
+
+
asn
AS
-
+
Autonomous System Number
-
+
+
+
+
+
+
mp-import
+
text
+
+
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+
+
mp-export
text
-
+
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
-
+
+
+
+
+
+
description
+
text
+
+
Description of the autonomous system
+
+
+
+
+
+
+
export
+
text
+
+
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
+
+
@@ -999,7 +1006,7 @@ av-signature is a MISP object available in JSON format at
+
@@ -1018,40 +1025,40 @@ av-signature is a MISP object available in JSON format at
A field to freely describe the bank account details.
-
-
-
-
-
-
-
currency-code
-
text
-
-
Currency of the account. ['USD', 'EUR']
-
-
-
-
-
-
-
status-code
-
text
-
-
Account status at the time of the transaction processed. ['A - Active', 'B - Inactive', 'C - Dormant']
-
-
+
client-number
text
-
+
Client number as seen by the bank.
-
+
-
closed
-
datetime
-
-
When the account was closed.
-
-
-
-
-
-
-
aba-rtn
-
aba-rtn
-
-
ABA routing transit number
-
-
-
-
-
-
-
beneficiary-comment
+
currency-code
text
-
-
Comment about the final beneficiary.
+
+
Currency of the account. ['USD', 'EUR']
-
-
-
-
-
-
iban
-
iban
-
-
IBAN of the bank account.
-
-
-
-
-
-
-
institution-name
-
text
-
-
Name of the bank or financial organisation.
-
-
-
-
-
-
-
account
-
bank-account-nr
-
-
Account number
-
-
-
-
-
-
-
date-balance
-
datetime
-
-
When the balance was reported.
-
-
-
-
-
-
-
report-code
-
text
-
-
Report code of the bank account. ['CTR Cash Transaction Report', 'STR Suspicious Transaction Report', 'EFT Electronic Funds Transfer', 'IFT International Funds Transfer', 'TFR Terror Financing Report', 'BCR Border Cash Report', 'UTR Unusual Transaction Report', 'AIF Additional Information File – Can be used for example to get full disclosure of transactions of an account for a period of time without reporting it as a CTR.', 'IRI Incoming Request for Information – International', 'ORI Outgoing Request for Information – International', 'IRD Incoming Request for Information – Domestic', 'ORD Outgoing Request for Information – Domestic']
-
-
-
-
-
-
-
personal-account-type
-
text
-
-
Account type. ['A - Business', 'B - Personal Current', 'C - Savings', 'D - Trust Account', 'E - Trading Account', 'O - Other']
-
-
-
-
-
-
-
non-banking-institution
-
boolean
-
-
A flag to define if this account belong to a non-banking organisation. If set to true, it’s a non-banking organisation.
-
-
-
-
-
-
-
text
-
text
-
-
A description of the bank account.
-
-
+
beneficiary
text
-
+
Final beneficiary of the bank account.
-
+
-
institution-code
+
opened
+
datetime
+
+
When the account was opened.
+
+
+
+
+
+
+
account-name
text
-
-
Institution code of the bank.
+
+
A field to freely describe the bank account details.
-
-
+
+
-
balance
+
personal-account-type
text
-
-
The balance of the account after the suspicious transaction was processed.
+
+
Account type. ['A - Business', 'B - Personal Current', 'C - Savings', 'D - Trust Account', 'E - Trading Account', 'O - Other']
-
-
-
-
-
-
swift
-
bic
-
-
SWIFT or BIC as defined in ISO 9362.
-
-
+
branch
text
-
+
Branch code or name
-
+
+
+
+
+
+
balance
+
text
+
+
The balance of the account after the suspicious transaction was processed.
+
+
+
+
+
+
+
status-code
+
text
+
+
Account status at the time of the transaction processed. ['A - Active', 'B - Inactive', 'C - Dormant']
+
+
+
+
+
+
+
iban
+
iban
+
+
IBAN of the bank account.
+
+
+
+
+
+
+
report-code
+
text
+
+
Report code of the bank account. ['CTR Cash Transaction Report', 'STR Suspicious Transaction Report', 'EFT Electronic Funds Transfer', 'IFT International Funds Transfer', 'TFR Terror Financing Report', 'BCR Border Cash Report', 'UTR Unusual Transaction Report', 'AIF Additional Information File – Can be used for example to get full disclosure of transactions of an account for a period of time without reporting it as a CTR.', 'IRI Incoming Request for Information – International', 'ORI Outgoing Request for Information – International', 'IRD Incoming Request for Information – Domestic', 'ORD Outgoing Request for Information – Domestic']
+
+
+
+
+
+
+
account
+
bank-account-nr
+
+
Account number
+
+
+
+
+
+
+
aba-rtn
+
aba-rtn
+
+
ABA routing transit number
+
+
+
+
+
+
+
swift
+
bic
+
+
SWIFT or BIC as defined in ISO 9362.
+
+
+
+
+
+
+
text
+
text
+
+
A description of the bank account.
+
+
+
+
+
+
+
non-banking-institution
+
boolean
+
+
A flag to define if this account belong to a non-banking organisation. If set to true, it’s a non-banking organisation.
+
+
+
+
+
+
+
closed
+
datetime
+
+
When the account was closed.
+
+
+
+
+
+
+
institution-name
+
text
+
+
Name of the bank or financial organisation.
+
+
@@ -1335,7 +1342,7 @@ cap-alert is a MISP object available in JSON format at
+
@@ -1352,132 +1359,132 @@ cap-alert is a MISP object available in JSON format at
The identifier of the sender of the alert message which identifies the originator of this alert. Guaranteed by assigner to be unique globally; e.g., may be based on an Internet domain name.
-
-
-
-
-
-
-
scope
-
text
-
-
The code denoting the intended distribution of the alert message. ['Public', 'Restricted', 'Private']
-
-
-
-
-
-
-
incident
-
text
-
-
The group listing naming the referent incident(s) of the alert message. (1) Used to collate multiple messages referring to different aspects of the same incident. (2) If multiple incident identifiers are referenced, they SHALL be separated by whitespace. Incident names including whitespace SHALL be surrounded by double-quotes.
-
-
-
-
-
-
msgType
text
-
+
The code denoting the nature of the alert message. ['Alert', 'Update', 'Cancel', 'Ack', 'Error']
-
+
source
text
-
+
The text identifying the source of the alert message. The particular source of this alert; e.g., an operator or a specific device.
-
-
-
-
-
-
code
-
text
-
-
The code denoting the special handling of the alert message.
-
-
-
-
-
-
-
sent
-
datetime
-
-
The time and date of the origination of the alert message.
-
-
-
-
-
-
-
references
-
text
-
-
The group listing identifying earlier message(s) referenced by the alert message. (1) The extended message identifier(s) (in the form sender,identifier,sent) of an earlier CAP message or messages referenced by this one. (2) If multiple messages are referenced, they SHALL be separated by whitespace.
-
-
-
-
-
-
-
restriction
-
text
-
-
The text describing the rule for limiting distribution of the restricted alert message.
-
-
-
-
-
-
-
identifier
-
text
-
-
The identifier of the alert message in a number or string uniquely identifying this message, assigned by the sender.
-
-
+
note
text
-
+
The text describing the purpose or significance of the alert message.
-
+
+
+
+
+
+
references
+
text
+
+
The group listing identifying earlier message(s) referenced by the alert message. (1) The extended message identifier(s) (in the form sender,identifier,sent) of an earlier CAP message or messages referenced by this one. (2) If multiple messages are referenced, they SHALL be separated by whitespace.
+
+
+
+
+
+
+
code
+
text
+
+
The code denoting the special handling of the alert message.
+
+
+
+
+
+
+
restriction
+
text
+
+
The text describing the rule for limiting distribution of the restricted alert message.
+
+
+
+
+
+
+
sent
+
datetime
+
+
The time and date of the origination of the alert message.
+
+
+
+
+
+
+
scope
+
text
+
+
The code denoting the intended distribution of the alert message. ['Public', 'Restricted', 'Private']
+
+
+
+
+
+
+
sender
+
text
+
+
The identifier of the sender of the alert message which identifies the originator of this alert. Guaranteed by assigner to be unique globally; e.g., may be based on an Internet domain name.
+
+
status
text
-
+
The code denoting the appropriate handling of the alert message. ['Actual', 'Exercise', 'System', 'Test', 'Draft']
-
+
addresses
text
-
+
The group listing of intended recipients of the alert message. (1) Required when <scope> is “Private”, optional when <scope> is “Public” or “Restricted”. (2) Each recipient SHALL be identified by an identifier or an address. (3) Multiple space-delimited addresses MAY be included. Addresses including whitespace MUST be enclosed in double-quotes.
-
+
+
+
+
+
+
incident
+
text
+
+
The group listing naming the referent incident(s) of the alert message. (1) Used to collate multiple messages referring to different aspects of the same incident. (2) If multiple incident identifiers are referenced, they SHALL be separated by whitespace. Incident names including whitespace SHALL be surrounded by double-quotes.
+
+
+
+
+
+
+
identifier
+
text
+
+
The identifier of the alert message in a number or string uniquely identifying this message, assigned by the sender.
+
+
@@ -1503,7 +1510,7 @@ cap-info is a MISP object available in JSON format at
+
@@ -1522,190 +1529,190 @@ cap-info is a MISP object available in JSON format at
The code denoting the language of the info sub-element of the alert message.
-
-
-
-
-
-
senderName
-
text
-
-
The text naming the originator of the alert message.
-
-
-
-
-
-
-
responseType
-
text
-
-
The code denoting the type of action recommended for the target audience. ['Shelter', 'Evacuate', 'Prepare', 'Execute', 'Avoid', 'Monitor', 'Assess', 'AllClear', 'None']
-
-
-
-
-
-
-
onset
-
datetime
-
-
The expected time of the beginning of the subject event of the alert message.
-
-
-
-
-
-
-
audience
-
text
-
-
The text describing the intended audience of the alert message.
-
-
-
-
-
-
-
effective
-
datetime
-
-
The effective time of the information of the alert message.
-
-
-
-
-
-
-
web
-
link
-
-
The identifier of the hyperlink associating additional information with the alert message.
-
-
-
-
-
-
-
certainty
-
text
-
-
The code denoting the certainty of the subject event of the alert message. For backward compatibility with CAP 1.0, the deprecated value of “Very Likely” SHOULD be treated as equivalent to “Likely”. ['Likely', 'Possible', 'Unlikely', 'Unknown']
-
-
+
parameter
text
-
+
A system-specific additional parameter associated with the alert message.
-
+
-
event
-
text
-
-
The text denoting the type of the subject event of the alert message.
-
-
-
-
-
-
-
expires
+
onset
datetime
-
-
The expiry time of the information of the alert message.
+
+
The expected time of the beginning of the subject event of the alert message.
-
-
-
-
-
-
urgency
-
text
-
-
The code denoting the urgency of the subject event of the alert message. ['Immediate', 'Expected', 'Future', 'Past', 'Unknown']
-
-
-
-
-
-
-
contact
-
text
-
-
The text describing the contact for follow-up and confirmation of the alert message.
-
-
-
-
-
-
-
instruction
-
text
-
-
The text describing the recommended action to be taken by recipients of the alert message.
-
-
-
-
-
-
-
eventCode
-
text
-
-
A system-specific code identifying the event type of the alert message.
-
-
+
description
text
-
+
The text describing the subject event of the alert message.
-
+
-
severity
+
contact
text
-
-
The code denoting the severity of the subject event of the alert message. ['Extreme', 'Severe', 'Moderate', 'Minor', 'Unknown']
+
+
The text describing the contact for follow-up and confirmation of the alert message.
-
-
-
-
-
-
category
-
text
-
-
The code denoting the category of the subject event of the alert message. ['Geo', 'Met', 'Safety', 'Security', 'Rescue', 'Fire', 'Health', 'Env', 'Transport', 'Infra', 'CBRNE', 'Other']
-
-
+
headline
text
-
+
The text headline of the alert message.
-
+
+
+
+
+
+
effective
+
datetime
+
+
The effective time of the information of the alert message.
+
+
+
+
+
+
+
instruction
+
text
+
+
The text describing the recommended action to be taken by recipients of the alert message.
+
+
+
+
+
+
+
event
+
text
+
+
The text denoting the type of the subject event of the alert message.
+
+
+
+
+
+
+
web
+
link
+
+
The identifier of the hyperlink associating additional information with the alert message.
+
+
+
+
+
+
+
category
+
text
+
+
The code denoting the category of the subject event of the alert message. ['Geo', 'Met', 'Safety', 'Security', 'Rescue', 'Fire', 'Health', 'Env', 'Transport', 'Infra', 'CBRNE', 'Other']
+
+
+
+
+
+
+
eventCode
+
text
+
+
A system-specific code identifying the event type of the alert message.
+
+
+
+
+
+
+
audience
+
text
+
+
The text describing the intended audience of the alert message.
+
+
+
+
+
+
+
responseType
+
text
+
+
The code denoting the type of action recommended for the target audience. ['Shelter', 'Evacuate', 'Prepare', 'Execute', 'Avoid', 'Monitor', 'Assess', 'AllClear', 'None']
+
+
+
+
+
+
+
severity
+
text
+
+
The code denoting the severity of the subject event of the alert message. ['Extreme', 'Severe', 'Moderate', 'Minor', 'Unknown']
+
+
+
+
+
+
+
expires
+
datetime
+
+
The expiry time of the information of the alert message.
+
+
+
+
+
+
+
senderName
+
text
+
+
The text naming the originator of the alert message.
+
+
+
+
+
+
+
certainty
+
text
+
+
The code denoting the certainty of the subject event of the alert message. For backward compatibility with CAP 1.0, the deprecated value of “Very Likely” SHOULD be treated as equivalent to “Likely”. ['Likely', 'Possible', 'Unlikely', 'Unknown']
+
+
+
+
+
+
+
urgency
+
text
+
+
The code denoting the urgency of the subject event of the alert message. ['Immediate', 'Expected', 'Future', 'Past', 'Unknown']
+
+
@@ -1731,7 +1738,7 @@ cap-resource is a MISP object available in JSON format at
+
@@ -1748,62 +1755,62 @@ cap-resource is a MISP object available in JSON format at
Last time this payment destination address has been seen
+
address
+
btc
+
+
Address used as a payment destination in a cryptocurrency
-
-
-
-
-
-
text
-
text
-
-
Free text value
-
-
-
+
+
symbol
text
-
+
The (uppercase) symbol of the cryptocurrency used. Symbol should be from https://coinmarketcap.com/all/views/all/ ['BTC', 'ETH', 'BCH', 'XRP', 'MIOTA', 'DASH', 'BTG', 'LTC', 'ADA', 'XMR', 'ETC', 'NEO', 'NEM', 'EOS', 'XLM', 'BCC', 'LSK', 'OMG', 'QTUM', 'ZEC', 'USDT', 'HSR', 'STRAT', 'WAVES', 'PPT']
-
+
+
+
+
+
+
last-seen
+
datetime
+
+
Last time this payment destination address has been seen
+
+
+
+
+
+
+
text
+
text
+
+
Free text value
+
+
first-seen
datetime
-
+
First time this payment destination address has been seen
-
+
-
-
address
-
btc
-
-
Address used as a payment destination in a cryptocurrency
-
-
-
-
-
@@ -1917,7 +1924,7 @@ cookie is a MISP object available in JSON format at
+
@@ -1934,52 +1941,52 @@ cookie is a MISP object available in JSON format at
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
-
+
+
+
+
+
+
cookie-value
+
text
+
+
Value of the cookie (if splitted)
+
+
cookie
cookie
-
+
Full cookie
-
+
+
+
+
+
+
cookie-name
+
text
+
+
Name of the cookie (if splitted)
+
+
@@ -2005,7 +2012,7 @@ course-of-action is a MISP object available in JSON format at
+
@@ -2022,82 +2029,82 @@ course-of-action is a MISP object available in JSON format at
When the paste has been accessible or seen for the last time.
-
-
-
-
-
-
-
paste
+
username
text
-
-
Raw text of the paste or post
+
+
User who posted the post.
-
-
-
-
-
-
origin
-
text
-
-
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
-
-
+
url
url
-
+
Link to the original source of the paste or post.
-
+
+
last-seen
+
datetime
+
+
When the paste has been accessible or seen for the last time.
+
+
+
+
+
+
title
text
-
+
Title of the paste or post.
-
+
first-seen
datetime
-
+
When the paste has been accessible or seen for the first time.
-
+
+
+
+
+
+
paste
+
text
+
+
Raw text of the paste or post
+
+
+
+
+
+
+
origin
+
text
+
+
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
+
+
@@ -5851,7 +5888,7 @@ pe is a MISP object available in JSON format at
+
@@ -5868,182 +5905,182 @@ pe is a MISP object available in JSON format at
Mother name, father, second name or other names following country’s regulation.
-
-
-
-
-
-
last-name
-
last-name
-
-
Last name of a natural person.
-
-
-
-
-
-
-
alias
-
text
-
-
Alias name or known as.
-
-
-
-
-
-
-
passport-number
-
passport-number
-
-
The passport number of a natural person.
-
-
-
-
-
-
-
redress-number
-
redress-number
-
-
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
-
-
-
-
-
-
-
identity-card-number
-
identity-card-number
-
-
The identity card number of a natural person.
-
-
-
-
-
-
-
first-name
-
first-name
-
-
First name of a natural person.
-
-
-
-
-
-
-
place-of-birth
-
place-of-birth
-
-
Place of birth of a natural person.
-
-
-
-
-
-
-
gender
-
gender
-
-
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
-
-
-
-
-
-
-
text
-
text
-
-
A description of the person or identity.
-
-
-
-
-
-
-
social-security-number
-
text
-
-
Social security number
-
-
-
-
-
-
-
date-of-birth
-
date-of-birth
-
-
Date of birth of a natural person (in YYYY-MM-DD format).
-
-
+
nationality
nationality
-
+
The nationality of a natural person.
-
+
+
last-name
+
last-name
+
+
Last name of a natural person.
+
+
+
+
+
+
+
text
+
text
+
+
A description of the person or identity.
+
+
+
+
+
+
+
passport-expiration
+
passport-expiration
+
+
The expiration date of a passport.
+
+
+
+
+
+
+
redress-number
+
redress-number
+
+
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
+
+
+
+
+
+
title
text
-
+
Title of the natural person such as Dr. or equivalent.
-
+
-
passport-country
-
passport-country
-
-
The country in which the passport was issued.
+
gender
+
gender
+
+
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
-
+
-
passport-expiration
-
passport-expiration
-
-
The expiration date of a passport.
+
place-of-birth
+
place-of-birth
+
+
Place of birth of a natural person.
-
+
+
+
date-of-birth
+
date-of-birth
+
+
Date of birth of a natural person (in YYYY-MM-DD format).
+
+
+
+
+
@@ -6455,7 +6492,7 @@ phone is a MISP object available in JSON format at
+
@@ -6472,105 +6509,105 @@ phone is a MISP object available in JSON format at
When the phone has been accessible or seen for the last time.
-
-
-
-
-
-
text
text
-
+
A description of the phone.
-
+
-
first-seen
+
last-seen
datetime
-
-
When the phone has been accessible or seen for the first time.
+
+
When the phone has been accessible or seen for the last time.
-
+
-
gummei
+
imsi
text
-
-
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
+
+
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
-
-
-
-
-
-
serial-number
-
text
-
-
Serial Number.
-
-
+
msisdn
text
-
+
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
-
+
+
+
+
+
+
gummei
+
text
+
+
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
+
+
imei
text
-
+
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
-
-
-
-
-
-
imsi
-
text
-
-
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
-
-
-
-
-
-
-
tmsi
-
text
-
-
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
-
-
+
guti
text
-
+
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
-
+
+
+
serial-number
+
text
+
+
Serial Number.
+
+
+
+
+
+
+
tmsi
+
text
+
+
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
+
+
+
+
+
+
+
first-seen
+
datetime
+
+
When the phone has been accessible or seen for the first time.
+
+
+
+
+
@@ -6593,7 +6630,7 @@ process is a MISP object available in JSON format at
+
@@ -6612,70 +6649,70 @@ process is a MISP object available in JSON format at
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
-
-
-
-
-
-
comment
-
comment
-
-
A description of the regular expression.
-
-
-
-
-
-
-
regexp-type
-
text
-
-
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
-
-
+
regexp
text
-
+
regexp
-
+
+
+
+
+
+
regexp-type
+
text
+
+
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
+
+
+
+
+
+
+
comment
+
comment
+
+
A description of the regular expression.
+
+
@@ -7037,7 +7074,7 @@ registry-key is a MISP object available in JSON format at
+
@@ -7056,73 +7093,73 @@ registry-key is a MISP object available in JSON format at
Hive used to store the registry key (file on disk)
-
+
+
+
+
+
+
data-type
+
text
+
+
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
+
+
key
regkey
-
+
Full key path
-
+
data
text
-
+
Data stored in the registry key
-
+
+
+
+
+
+
name
+
text
+
+
Name of the registry key
+
+
root-keys
text
-
+
Root key of the Windows registry (extracted from the key) ['HKCC', 'HKCR', 'HKCU', 'HKDD', 'HKEY_CLASSES_ROOT', 'HKEY_CURRENT_CONFIG', 'HKEY_CURRENT_USER', 'HKEY_DYN_DATA', 'HKEY_LOCAL_MACHINE', 'HKEY_PERFORMANCE_DATA', 'HKEY_USERS', 'HKLM', 'HKPD', 'HKU']
-
+
-
name
-
text
-
-
Name of the registry key
-
-
-
-
-
-
last-modified
datetime
-
+
Last time the registry key has been modified
-
+
-
-
data-type
-
text
-
-
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
-
-
-
-
-
@@ -7145,7 +7182,7 @@ report is a MISP object available in JSON format at
+
@@ -7164,20 +7201,20 @@ report is a MISP object available in JSON format at
Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts..
+
+
+
+
+
+
+
+
+script is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP.
+
+
+
+
+
+
+
+
+
+
+
+
+
+
Object attribute
+
MISP attribute type
+
Description
+
Disable correlation
+
+
+
+
+
language
+
text
+
+
Scripting language used for the script. ['PowerShell', 'VBScript', 'Bash', 'Lua', 'JavaScript', 'AppleScript', 'AWK', 'Python', 'Perl', 'Ruby', 'Winbatch', 'AutoIt']
+
+
+
+
+
+
+
state
+
text
+
+
Known state of the script. ['Malicious', 'Unknown', 'Harmless', 'Trusted']
+shortened-link is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP.
+
+
+
+
+
+
+
+
+
+
+
+
+
+
Object attribute
+
MISP attribute type
+
Description
+
Disable correlation
+
+
+
+
+
text
+
text
+
+
Description and context of the shortened URL
+
+
+
+
+
+
+
shortened-url
+
url
+
+
Shortened URL
+
+
+
+
+
+
+
credential
+
text
+
+
Credential (username, password)
+
+
+
+
+
+
+
redirect-url
+
url
+
+
Redirected to URL
+
+
+
+
+
+
+
domain
+
domain
+
+
Full domain
+
+
+
+
+
+
+
first-seen
+
datetime
+
+
First time this shortened URL has been seen
+
+
@@ -7507,7 +7730,7 @@ ss7-attack is a MISP object available in JSON format at
+
@@ -7524,265 +7747,265 @@ ss7-attack is a MISP object available in JSON format at
Type of funds used to finalize a transaction. ['A Deposit', 'C Currency exchange', 'D Casino chips', 'E Bank draft', 'F Money order', 'G Traveler’s cheques', 'H Life insurance policy', 'I Real estate', 'J Securities', 'K Cash', 'O Other', 'P Cheque']
-
+
-
from-country
+
amount
text
-
-
Origin country of a transaction.
+
+
The value of the transaction in local currency.
-
-
-
-
-
-
transaction-number
-
text
-
-
A unique number identifying a transaction.
-
-
-
-
-
-
-
authorized
-
text
-
-
Person who autorized the transaction.
-
-
+
transmode-code
text
-
+
How the transaction was conducted.
-
+
-
from-funds-code
+
from-country
text
-
-
Type of funds used to initiate a transaction. ['A Deposit', 'C Currency exchange', 'D Casino chips', 'E Bank draft', 'F Money order', 'G Traveler’s cheques', 'H Life insurance policy', 'I Real estate', 'J Securities', 'K Cash', 'O Other', 'P Cheque']
+
+
Origin country of a transaction.
-
-
-
-
-
-
date
-
datetime
-
-
Date and time of the transaction.
-
-
-
-
-
-
-
text
-
text
-
-
A description of the transaction.
-
-
-
-
-
-
-
location
-
text
-
-
Location where the transaction took place.
-
-
-
-
-
-
-
amount
-
text
-
-
The value of the transaction in local currency.
-
-
-
-
-
-
-
teller
-
text
-
-
Person who conducted the transaction.
-
-
-
-
-
-
-
transmode-comment
-
text
-
-
Comment describing transmode-code, if needed.
-
-
+
date-posting
datetime
-
+
Date of posting, if different from date of transaction.
-
+
+
+
+
+
+
transmode-comment
+
text
+
+
Comment describing transmode-code, if needed.
+
+
+
+
+
+
+
date
+
datetime
+
+
Date and time of the transaction.
+
+
+
+
+
+
+
text
+
text
+
+
A description of the transaction.
+
+
+
+
+
+
+
to-country
+
text
+
+
Target country of a transaction.
+
+
+
+
+
+
+
from-funds-code
+
text
+
+
Type of funds used to initiate a transaction. ['A Deposit', 'C Currency exchange', 'D Casino chips', 'E Bank draft', 'F Money order', 'G Traveler’s cheques', 'H Life insurance policy', 'I Real estate', 'J Securities', 'K Cash', 'O Other', 'P Cheque']
+
+
+
+
+
+
+
transaction-number
+
text
+
+
A unique number identifying a transaction.
+
+
+
+
+
+
+
location
+
text
+
+
Location where the transaction took place.
+
+
+
+
+
+
+
authorized
+
text
+
+
Person who autorized the transaction.
+
+
@@ -8609,7 +8832,7 @@ url is a MISP object available in JSON format at
+
@@ -8626,152 +8849,152 @@ url is a MISP object available in JSON format at
Vulnerability ID (generally CVE, but not necessarely). The id is not required as the object itself has an UUID and the CVE id can updated later.
-
-
-
-
-
-
-
references
-
link
-
-
External references
-
-
+
modified
datetime
-
+
Last modification date
-
-
-
-
-
-
created
-
datetime
-
-
First time when the vulnerability was discovered
-
-
+
published
datetime
-
+
Initial publication date
-
+
-
state
-
text
-
-
State of the vulnerability. A vulnerability can have multiple states depending of the current actions performed. ['Published', 'Embargo', 'Reviewed', 'Vulnerability ID Assigned', 'Reported', 'Fixed']
+
id
+
vulnerability
+
+
Vulnerability ID (generally CVE, but not necessarely). The id is not required as the object itself has an UUID and the CVE id can updated later.
-
-
+
+
+
+
+
+
references
+
link
+
+
External references
+
+
+
summary
text
-
+
Summary of the vulnerability
-
+
+
state
+
text
+
+
State of the vulnerability. A vulnerability can have multiple states depending of the current actions performed. ['Published', 'Embargo', 'Reviewed', 'Vulnerability ID Assigned', 'Reported', 'Fixed']
+
+
+
+
+
+
vulnerable_configuration
text
-
+
The vulnerable configuration is described in CPE format
-
+
+
+
created
+
datetime
+
+
First time when the vulnerability was discovered
+
+
+
+
+
@@ -9171,7 +9394,7 @@ whois is a MISP object available in JSON format at
+
@@ -9188,132 +9411,132 @@ whois is a MISP object available in JSON format at