diff --git a/objects.html b/objects.html index 88ae11a..42cee29 100755 --- a/objects.html +++ b/objects.html @@ -444,6 +444,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
sensor
+type
text
The AIL sensor uuid where the leak was processed and analysed.
--
duplicate
text
Duplicate of the existing leaks.
+Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
@@ -595,30 +587,10 @@ ail-leak is a MISP object available in JSON format at
first-seen
datetime
raw-data
attachment
When the leak has been accessible or seen for the first time.
--
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
--
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
+Raw data as received by the AIL sensor compressed and encoded in Base64.
@@ -635,6 +607,36 @@ ail-leak is a MISP object available in JSON format at
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
++
sensor
text
The AIL sensor uuid where the leak was processed and analysed.
++
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
++
origin
text
type
text
first-seen
datetime
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
--
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
+When the leak has been accessible or seen for the first time.
duplicate
text
Duplicate of the existing leaks.
++
creation-date
-datetime
Initial creation of the annotation
--
format
text
Format of the annotation ['text', 'markdown', 'asciidoctor', 'MultiMarkdown', 'GFM', 'pandoc', 'Fountain', 'CommonWork', 'kramdown-rfc2629', 'rfc7328', 'Extra']
--
modification-date
datetime
ref
link
Reference(s) to the annotation
--
type
text
format
text
Format of the annotation ['text', 'markdown', 'asciidoctor', 'MultiMarkdown', 'GFM', 'pandoc', 'Fountain', 'CommonWork', 'kramdown-rfc2629', 'rfc7328', 'Extra']
++
ref
link
Reference(s) to the annotation
++
creation-date
datetime
Initial creation of the annotation
++
first-seen
-datetime
asn
AS
First time the ASN was seen
--
description
text
Description of the autonomous system
--
export
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
import
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
+Autonomous System Number
@@ -909,20 +881,20 @@ asn is a MISP object available in JSON format at
mp-export
text
subnet-announced
ip-src
This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+Subnet announced
asn
AS
export
text
Autonomous System Number
+The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
@@ -939,20 +911,50 @@ asn is a MISP object available in JSON format at
mp-import
description
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
+Description of the autonomous system
subnet-announced
ip-src
mp-export
text
Subnet announced
+This attribute performs the same function as the export attribute above. The difference is that mp-export allows both IPv4 and IPv6 address families to be specified. The export is described in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
++
first-seen
datetime
First time the ASN was seen
++
import
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
++
mp-import
text
The inbound IPv4 or IPv6 routing policy of the AS in RFC 4012 – Routing Policy Specification Language next generation (RPSLng), section 4.5. format
@@ -997,6 +999,26 @@ av-signature is a MISP object available in JSON format at
text
text
Free text value to attach to the file
++
datetime
datetime
Datetime
++
signature
text
An object describing bank account information based on account description from goAML 4.0..
+datetime |
-datetime |
++ + | ++bank-account is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +|||||
---|---|---|---|---|---|---|---|---|
branch |
+text |
- Datetime +Branch code or name |
@@ -1030,7 +1090,187 @@ av-signature is a MISP object available in JSON format at text |
text |
- Free text value to attach to the file +A description of the bank account. + |
+
+ + |
+||
institution-code |
+text |
+
+ Name of the bank or financial organisation. + |
+
+ + |
+|||||
iban |
+iban |
+
+ IBAN of the bank account. + |
+
+ + |
+|||||
account-name |
+text |
+
+ A field to freely describe the bank account details. + |
+
+ + |
+|||||
date-balance |
+datetime |
+
+ When the balance was reported. + |
+
+ + |
+|||||
personal-account-type |
+text |
+
+ Account type. ['A - Business', 'B - Personal Current', 'C - Savings', 'D - Trust Account', 'E - Trading Account', 'O - Other'] + |
+
+ + |
+|||||
comments |
+text |
+
+ Comments about the bank account. + |
+
+ + |
+|||||
beneficiary |
+text |
+
+ Final beneficiary of the bank account. + |
+
+ + |
+|||||
account |
+bank-account-nr |
+
+ Account number + |
+
+ + |
+|||||
status-code |
+text |
+
+ Account status at the time of the transaction processed. ['A - Active', 'B - Inactive', 'C - Dormant'] + |
+
+ + |
+|||||
report-code |
+text |
+
+ Report code of the bank account. ['CTR Cash Transaction Report', 'STR Suspicious Transaction Report', 'EFT Electronic Funds Transfer', 'IFT International Funds Transfer', 'TFR Terror Financing Report', 'BCR Border Cash Report', 'UTR Unusual Transaction Report', 'AIF Additional Information File – Can be used for example to get full disclosure of transactions of an account for a period of time without reporting it as a CTR.', 'IRI Incoming Request for Information – International', 'ORI Outgoing Request for Information – International', 'IRD Incoming Request for Information – Domestic', 'ORD Outgoing Request for Information – Domestic'] + |
+
+ + |
+|||||
swift |
+bic |
+
+ SWIFT or BIC as defined in ISO 9362. + |
+
+ + |
+|||||
currency-code |
+text |
+
+ Currency of the account. ['USD', 'EUR'] + |
+
+ + |
+|||||
balance |
+text |
+
+ The balance of the account after the suspicious transaction was processed. + |
+
+ + |
+|||||
opened |
+datetime |
+
+ When the account was opened. + |
+
+ + |
+|||||
beneficiary-comment |
+text |
+
+ Comment about the final beneficiary. + |
+
+ + |
+|||||
closed |
+datetime |
+
+ When the account was closed. + |
+
+ + |
+|||||
client-_number |
+text |
+
+ Client number as seen by the bank. + |
+
+ + |
+|||||
non-banking-institution |
+boolean |
+
+ A flag to define if this account belong to a non-banking organisation. If set to true, it’s a non-banking organisation. |
@@ -1075,20 +1315,30 @@ coin-address is a MISP object available in JSON format at first-seen |
-datetime |
+text |
+text |
- First time this payment destination address has been seen +Free text value |
|
text |
-text |
+address |
+btc |
- Free text value +Address used as a payment destination in a cryptocurrency + |
+
+ + |
+|||
first-seen |
+datetime |
+
+ First time this payment destination address has been seen |
||||||
address |
-btc |
-
- Address used as a payment destination in a cryptocurrency - |
-
- - |
-
cookie
-cookie
cookie-value
text
Full cookie
+Value of the cookie (if splitted)
@@ -1203,10 +1443,10 @@ cookie is a MISP object available in JSON format at
cookie-value
text
cookie
cookie
Value of the cookie (if splitted)
+Full cookie
@@ -1251,16 +1491,6 @@ credential is a MISP object available in JSON format at
text
text
A description of the credential(s)
--
username
text
format
text
text
Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
+A description of the credential(s)
+
notification
password
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
+Password
@@ -1311,10 +1541,20 @@ credential is a MISP object available in JSON format at
password
format
text
Password
+Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
++
notification
text
Mention of any notification(s) towards the potential owner(s) of the credential(s) ['victim-notified', 'service-notified', 'none']
@@ -1369,6 +1609,26 @@ credit-card is a MISP object available in JSON format at
expiration
datetime
Maximum date of validity
++
comment
comment
A description of the card.
++
version
text
expiration
datetime
Maximum date of validity
--
cc-number
cc-number
comment
comment
A description of the card.
--
ip-dst
+ip-dst
Destination IP (victim)
++
ip-src
ip-src
IP address originating the attack
++
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
++
dst-port
port
Destination port of the attack
++
first-seen
datetime
src-port
port
Port originating the attack
--
total-pps
counter
src-port
port
Port originating the attack
++
domain-dst
domain
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
--
ip-dst
ip-dst
Destination IP (victim)
--
ip-src
ip-src
IP address originating the attack
--
dst-port
port
Destination port of the attack
--
Origin-Realm
-text
Origin-Realm.
--
text
text
Destination-Realm
text
Destination-Realm.
++
Destination-Host
text
Destination-Host.
++
Origin-Realm
text
Origin-Realm.
++
IdrFlags
text
Username
text
first-seen
datetime
Username (in this case, usually the IMSI).
+When the attack has been seen for the first time.
+
SessionId
-text
Session-ID.
--
first-seen
datetime
When the attack has been seen for the first time.
--
Origin-Host
text
Destination-Host
text
Destination-Host.
--
Destination-Realm
text
Destination-Realm.
--
category
text
SessionId
text
Session-ID.
++
Username
text
Username (in this case, usually the IMSI).
++
ip
+ip-dst
IP Address
++
text
text
ip
ip-dst
IP Address
--
arch
+text
Architecture of the ELF file ['None', 'M32', 'SPARC', 'i386', 'ARCH_68K', 'ARCH_88K', 'IAMCU', 'ARCH_860', 'MIPS', 'S370', 'MIPS_RS3_LE', 'PARISC', 'VPP500', 'SPARC32PLUS', 'ARCH_960', 'PPC', 'PPC64', 'S390', 'SPU', 'V800', 'FR20', 'RH32', 'RCE', 'ARM', 'ALPHA', 'SH', 'SPARCV9', 'TRICORE', 'ARC', 'H8_300', 'H8_300H', 'H8S', 'H8_500', 'IA_64', 'MIPS_X', 'COLDFIRE', 'ARCH_68HC12', 'MMA', 'PCP', 'NCPU', 'NDR1', 'STARCORE', 'ME16', 'ST100', 'TINYJ', 'x86_64', 'PDSP', 'PDP10', 'PDP11', 'FX66', 'ST9PLUS', 'ST7', 'ARCH_68HC16', 'ARCH_68HC11', 'ARCH_68HC08', 'ARCH_68HC05', 'SVX', 'ST19', 'VAX', 'CRIS', 'JAVELIN', 'FIREPATH', 'ZSP', 'MMIX', 'HUANY', 'PRISM', 'AVR', 'FR30', 'D10V', 'D30V', 'V850', 'M32R', 'MN10300', 'MN10200', 'PJ', 'OPENRISC', 'ARC_COMPACT', 'XTENSA', 'VIDEOCORE', 'TMM_GPP', 'NS32K', 'TPC', 'SNP1K', 'ST200', 'IP2K', 'MAX', 'CR', 'F2MC16', 'MSP430', 'BLACKFIN', 'SE_C33', 'SEP', 'ARCA', 'UNICORE', 'EXCESS', 'DXP', 'ALTERA_NIOS2', 'CRX', 'XGATE', 'C166', 'M16C', 'DSPIC30F', 'CE', 'M32C', 'TSK3000', 'RS08', 'SHARC', 'ECOG2', 'SCORE7', 'DSP24', 'VIDEOCORE3', 'LATTICEMICO32', 'SE_C17', 'TI_C6000', 'TI_C2000', 'TI_C5500', 'MMDSP_PLUS', 'CYPRESS_M8C', 'R32C', 'TRIMEDIA', 'HEXAGON', 'ARCH_8051', 'STXP7X', 'NDS32', 'ECOG1', 'ECOG1X', 'MAXQ30', 'XIMO16', 'MANIK', 'CRAYNV2', 'RX', 'METAG', 'MCST_ELBRUS', 'ECOG16', 'CR16', 'ETPU', 'SLE9X', 'L10M', 'K10M', 'AARCH64', 'AVR32', 'STM8', 'TILE64', 'TILEPRO', 'CUDA', 'TILEGX', 'CLOUDSHIELD', 'COREA_1ST', 'COREA_2ND', 'ARC_COMPACT2', 'OPEN8', 'RL78', 'VIDEOCORE5', 'ARCH_78KOR', 'ARCH_56800EX', 'BA1', 'BA2', 'XCORE', 'MCHP_PIC', 'INTEL205', 'INTEL206', 'INTEL207', 'INTEL208', 'INTEL209', 'KM32', 'KMX32', 'KMX16', 'KMX8', 'KVARC', 'CDP', 'COGE', 'COOL', 'NORC', 'CSR_KALIMBA', 'AMDGPU']
++
number-sections
counter
arch
text
Architecture of the ELF file ['None', 'M32', 'SPARC', 'i386', 'ARCH_68K', 'ARCH_88K', 'IAMCU', 'ARCH_860', 'MIPS', 'S370', 'MIPS_RS3_LE', 'PARISC', 'VPP500', 'SPARC32PLUS', 'ARCH_960', 'PPC', 'PPC64', 'S390', 'SPU', 'V800', 'FR20', 'RH32', 'RCE', 'ARM', 'ALPHA', 'SH', 'SPARCV9', 'TRICORE', 'ARC', 'H8_300', 'H8_300H', 'H8S', 'H8_500', 'IA_64', 'MIPS_X', 'COLDFIRE', 'ARCH_68HC12', 'MMA', 'PCP', 'NCPU', 'NDR1', 'STARCORE', 'ME16', 'ST100', 'TINYJ', 'x86_64', 'PDSP', 'PDP10', 'PDP11', 'FX66', 'ST9PLUS', 'ST7', 'ARCH_68HC16', 'ARCH_68HC11', 'ARCH_68HC08', 'ARCH_68HC05', 'SVX', 'ST19', 'VAX', 'CRIS', 'JAVELIN', 'FIREPATH', 'ZSP', 'MMIX', 'HUANY', 'PRISM', 'AVR', 'FR30', 'D10V', 'D30V', 'V850', 'M32R', 'MN10300', 'MN10200', 'PJ', 'OPENRISC', 'ARC_COMPACT', 'XTENSA', 'VIDEOCORE', 'TMM_GPP', 'NS32K', 'TPC', 'SNP1K', 'ST200', 'IP2K', 'MAX', 'CR', 'F2MC16', 'MSP430', 'BLACKFIN', 'SE_C33', 'SEP', 'ARCA', 'UNICORE', 'EXCESS', 'DXP', 'ALTERA_NIOS2', 'CRX', 'XGATE', 'C166', 'M16C', 'DSPIC30F', 'CE', 'M32C', 'TSK3000', 'RS08', 'SHARC', 'ECOG2', 'SCORE7', 'DSP24', 'VIDEOCORE3', 'LATTICEMICO32', 'SE_C17', 'TI_C6000', 'TI_C2000', 'TI_C5500', 'MMDSP_PLUS', 'CYPRESS_M8C', 'R32C', 'TRIMEDIA', 'HEXAGON', 'ARCH_8051', 'STXP7X', 'NDS32', 'ECOG1', 'ECOG1X', 'MAXQ30', 'XIMO16', 'MANIK', 'CRAYNV2', 'RX', 'METAG', 'MCST_ELBRUS', 'ECOG16', 'CR16', 'ETPU', 'SLE9X', 'L10M', 'K10M', 'AARCH64', 'AVR32', 'STM8', 'TILE64', 'TILEPRO', 'CUDA', 'TILEGX', 'CLOUDSHIELD', 'COREA_1ST', 'COREA_2ND', 'ARC_COMPACT2', 'OPEN8', 'RL78', 'VIDEOCORE5', 'ARCH_78KOR', 'ARCH_56800EX', 'BA1', 'BA2', 'XCORE', 'MCHP_PIC', 'INTEL205', 'INTEL206', 'INTEL207', 'INTEL208', 'INTEL209', 'KM32', 'KMX32', 'KMX16', 'KMX8', 'KVARC', 'CDP', 'COGE', 'COOL', 'NORC', 'CSR_KALIMBA', 'AMDGPU']
--
type
text
name
type
text
Name of the section
+Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
sha512
sha512
text
text
Secure Hash Algorithm 2 (512 bits)
+Free text value to attach to the section
+
sha224
-sha224
name
text
Secure Hash Algorithm 2 (224 bits)
+Name of the section
+
sha512/224
sha512/224
flag
text
Secure Hash Algorithm 2 (224 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
+Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
@@ -2049,16 +2269,46 @@ elf-section is a MISP object available in JSON format at
text
text
md5
md5
Free text value to attach to the section
+[Insecure] MD5 hash (128 bits)
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha256
sha256
flag
text
sha512/224
sha512/224
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
+Secure Hash Algorithm 2 (224 bits)
+
type
text
sha224
sha224
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (224 bits)
@@ -2147,36 +2387,6 @@ email is a MISP object available in JSON format at
to-display-name
email-dst-display-name
Display name of the receiver
--
attachment
email-attachment
Attachment
--
cc
email-dst
Carbon copy
--
header
email-header
screenshot
attachment
Screenshot of email
--
return-path
text
Message return path
--
message-id
email-message-id
Message ID
--
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
--
to
email-dst
subject
email-subject
message-id
email-message-id
Subject
--
thread-index
email-thread-index
Identifies a particular conversation thread
--
reply-to
email-reply-to
Email address the reply will be sent to
+Message ID
@@ -2287,6 +2437,16 @@ email is a MISP object available in JSON format at
attachment
email-attachment
Attachment
++
send-date
datetime
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
++
subject
email-subject
Subject
++
screenshot
attachment
Screenshot of email
++
to-display-name
email-dst-display-name
Display name of the receiver
++
cc
email-dst
Carbon copy
++
return-path
text
Message return path
++
reply-to
email-reply-to
Email address the reply will be sent to
++
from
email-src
thread-index
email-thread-index
Identifies a particular conversation thread
++
authentihash
-authentihash
certificate
x509-fingerprint-sha1
Authenticode executable signature hash
+Certificate value if the binary is signed with another authentication scheme than authenticode
text
text
Free text value to attach to the file
++
sha1
sha1
filename
filename
state
text
Filename on disk
+State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
sha224
sha224
mimetype
text
Secure Hash Algorithm 2 (224 bits)
+Mime type
++
entropy
float
Entropy of the whole file
++
pattern-in-file
pattern-in-file
Pattern that can be found in the file
certificate
x509-fingerprint-sha1
sha384
sha384
Certificate value if the binary is signed with another authentication scheme than authenticode
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
+Secure Hash Algorithm 2 (384 bits)
@@ -2425,80 +2685,10 @@ file is a MISP object available in JSON format at
sha384
sha384
authentihash
authentihash
Secure Hash Algorithm 2 (384 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
text
text
Free text value to attach to the file
--
entropy
float
Entropy of the whole file
--
mimetype
text
Mime type
--
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
state
text
State of the file ['Malicious', 'Harmless', 'Signed', 'Revoked', 'Expired', 'Trusted']
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
+Authenticode executable signature hash
@@ -2525,6 +2715,36 @@ file is a MISP object available in JSON format at
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
malware-sample
malware-sample
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
filename
filename
Filename on disk
++
ssdeep
ssdeep
first-seen
datetime
When the location was seen for the first time.
--
text
text
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
--
region
text
Region.
--
altitude
float
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
last-seen
datetime
city
text
City.
++
region
text
Region.
++
country
text
city
text
first-seen
datetime
City.
+When the location was seen for the first time.
+
+
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
++
longitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
+
GtpImsi
+text
GTP IMSI (International mobile subscriber identity).
++
text
text
ipSrc
ip-src
IP source address.
++
GtpMsisdn
text
GTP MSISDN.
++
GtpImei
text
GTP IMEI (International Mobile Equipment Identity).
++
ipDest
ip-dst
IP destination address.
++
GtpServingNetwork
text
first-seen
datetime
When the attack has been seen for the first time.
++
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
++
GtpVersion
text
GTP version ['0', '1', '2']
++
PortSrc
port
GtpMsisdn
text
GTP MSISDN.
--
first-seen
datetime
When the attack has been seen for the first time.
--
PortDest
text
ipSrc
ip-src
IP source address.
--
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
--
GtpImei
text
GTP IMEI (International Mobile Equipment Identity).
--
ipDest
ip-dst
IP destination address.
--
GtpVersion
text
GTP version ['0', '1', '2']
--
GtpImsi
text
GTP IMSI (International mobile subscriber identity).
--
referer
-referer
text
text
This is the address of the previous web page from which a link to the currently requested page was followed
+HTTP Request comment
++
uri
uri
Request URI
@@ -2899,20 +3149,10 @@ http-request is a MISP object available in JSON format at
url
url
cookie
text
Full HTTP Request URL
--
host
hostname
The domain name of the server
+An HTTP cookie previously sent by the server with Set-Cookie
@@ -2929,10 +3169,10 @@ http-request is a MISP object available in JSON format at
user-agent
user-agent
host
hostname
The user agent string of the user agent
+The domain name of the server
@@ -2949,30 +3189,20 @@ http-request is a MISP object available in JSON format at
text
text
user-agent
user-agent
HTTP Request comment
--
cookie
text
An HTTP cookie previously sent by the server with Set-Cookie
+The user agent string of the user agent
proxy-user
text
referer
referer
HTTP Proxy Username
+This is the address of the previous web page from which a link to the currently requested page was followed
@@ -2999,10 +3229,20 @@ http-request is a MISP object available in JSON format at
uri
uri
url
url
Request URI
+Full HTTP Request URL
++
proxy-user
text
HTTP Proxy Username
@@ -3057,20 +3297,20 @@ ip-port is a MISP object available in JSON format at
first-seen
last-seen
datetime
First time the tuple has been seen
+Last time the tuple has been seen
src-port
dst-port
port
Source port
+Destination port
@@ -3087,20 +3327,20 @@ ip-port is a MISP object available in JSON format at
last-seen
first-seen
datetime
Last time the tuple has been seen
+First time the tuple has been seen
dst-port
src-port
port
Destination port
+Source port
@@ -3145,36 +3385,6 @@ ja3 is a MISP object available in JSON format at
first-seen
datetime
First seen of the SSL/TLS handshake
--
description
text
Type of detected software ie software, malware
--
last-seen
datetime
Last seen of the SSL/TLS handshake
--
ip-dst
ip-dst
description
text
Type of detected software ie software, malware
++
first-seen
datetime
First seen of the SSL/TLS handshake
++
ja3-fingerprint-md5
md5
last-seen
datetime
Last seen of the SSL/TLS handshake
++
number-sections
-counter
Number of sections
--
name
type
text
Binary’s name
+Type of Mach-O ['BUNDLE', 'CORE', 'DSYM', 'DYLIB', 'DYLIB_STUB', 'DYLINKER', 'EXECUTE', 'FVMLIB', 'KEXT_BUNDLE', 'OBJECT', 'PRELOAD']
@@ -3273,20 +3503,30 @@ macho is a MISP object available in JSON format at
type
entrypoint-address
text
Type of Mach-O ['BUNDLE', 'CORE', 'DSYM', 'DYLIB', 'DYLIB_STUB', 'DYLINKER', 'EXECUTE', 'FVMLIB', 'KEXT_BUNDLE', 'OBJECT', 'PRELOAD']
+Address of the entry point
++
name
text
Binary’s name
entrypoint-address
text
number-sections
counter
Address of the entry point
+Number of sections
@@ -3331,26 +3571,16 @@ macho-section is a MISP object available in JSON format at
name
text
text
Name of the section
+Free text value to attach to the section
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha1
sha1
sha224
sha224
name
text
Secure Hash Algorithm 2 (224 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
+Name of the section
@@ -3421,16 +3621,46 @@ macho-section is a MISP object available in JSON format at
text
text
md5
md5
Free text value to attach to the section
+[Insecure] MD5 hash (128 bits)
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha256
sha256
sha512/256
sha512/256
sha512/224
sha512/224
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (224 bits)
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
@@ -3499,10 +3739,40 @@ microblog is a MISP object available in JSON format at
username
type
text
Username who posted the microblog post
+Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
++
removal-date
datetime
When the microblog post was removed
++
modification-date
datetime
Last update of the microblog post
++
link
url
Link into the microblog post
@@ -3529,10 +3799,10 @@ microblog is a MISP object available in JSON format at
modification-date
datetime
username
text
Last update of the microblog post
+Username who posted the microblog post
type
text
Type of the microblog post ['Twitter', 'Facebook', 'LinkedIn', 'Reddit', 'Google+', 'Instagram', 'Forum', 'Other']
--
link
url
Link into the microblog post
--
removal-date
datetime
When the microblog post was removed
--
flow-count
+ip_version
counter
Flows counted in this flow
+IP version of this flow
src-port
port
Source port of the netflow
--
src-as
AS
Source AS number for this flow
--
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
--
protocol
text
Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
--
last-packet-seen
datetime
Last packet seen in this flow
--
dst-as
AS
Destination AS number for this flow
--
packet-count
counter
Packets counted in this flow
--
direction
text
Direction of this flow ['Ingress', 'Egress']
--
tcp-flags
text
TCP flags of the flow
--
ip-protocol-number
size-in-bytes
IP protocol number of this flow
--
first-packet-seen
datetime
First packet seen in this flow
--
dst-port
port
ip-protocol-number
size-in-bytes
IP protocol number of this flow
++
ip-dst
ip-dst
tcp-flags
text
TCP flags of the flow
++
first-packet-seen
datetime
First packet seen in this flow
++
packet-count
counter
Packets counted in this flow
++
src-port
port
Source port of the netflow
++
direction
text
Direction of this flow ['Ingress', 'Egress']
++
dst-as
AS
Destination AS number for this flow
++
flow-count
counter
Flows counted in this flow
++
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
++
src-as
AS
Source AS number for this flow
++
last-packet-seen
datetime
Last packet seen in this flow
++
byte-count
counter
ip_version
counter
protocol
text
IP version of this flow
+Protocol used for this flow ['TCP', 'UDP', 'ICMP', 'IP']
+
sensor_id
+text
text
Sensor information where the record was seen
+Description of the passive DNS record.
+
time_first
datetime
count
counter
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
+How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers.
+
zone_time_first
time_last
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
+Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
+
+
rrtype
text
Resource Record type as seen by the passive DNS. ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
++
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import.
+
+
zone_time_last
datetime
sensor_id
text
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
+Sensor information where the record was seen
+
time_last
-datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
--
text
text
-
-
rrtype
text
Resource Record type as seen by the passive DNS ['A', 'AAAA', 'CNAME', 'PTR', 'SOA', 'TXT', 'DNAME', 'NS', 'SRV', 'RP', 'NAPTR', 'HINFO', 'A6']
--
rrname
text
Resource Record name of the queried resource
--
count
counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
--
origin
text
Origin of the Passive DNS response
+
rrname
text
Resource Record name of the queried resource.
+
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
++
first-seen
+last-seen
datetime
When the paste has been accessible or seen for the first time.
+When the paste has been accessible or seen for the last time.
@@ -4081,6 +4321,26 @@ paste is a MISP object available in JSON format at
origin
text
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
++
first-seen
datetime
When the paste has been accessible or seen for the first time.
++
title
text
origin
text
Original source of the paste or post. ['pastebin.com', 'pastebin.com_pro', 'pastie.org', 'slexy.org', 'gist.github.com', 'codepad.org', 'safebin.net', 'hastebin.com', 'ghostbin.com']
--
last-seen
datetime
When the paste has been accessible or seen for the last time.
--
internal-filename
+filename
InternalFilename in the resources
++
number-sections
counter
product-version
company-name
text
ProductVersion in the resources
--
legal-copyright
text
LegalCopyright in the resources
--
imphash
imphash
Hash (md5) calculated from the import table
--
original-filename
filename
OriginalFilename in the resources
--
text
text
Free text value to attach to the PE
--
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
+CompanyName in the resources
@@ -4249,10 +4449,70 @@ pe is a MISP object available in JSON format at
internal-filename
imphash
imphash
Hash (md5) calculated from the import table
++
lang-id
text
Lang ID in the resources
++
text
text
Free text value to attach to the PE
++
product-version
text
ProductVersion in the resources
++
original-filename
filename
InternalFilename in the resources
+OriginalFilename in the resources
++
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
++
legal-copyright
text
LegalCopyright in the resources
@@ -4269,16 +4529,6 @@ pe is a MISP object available in JSON format at
lang-id
text
Lang ID in the resources
--
product-name
text
company-name
text
CompanyName in the resources
--
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
--
impfuzzy
impfuzzy
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
++
entrypoint-address
text
name
text
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
+Free text value to attach to the section
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha1
sha1
sha224
sha224
name
text
Secure Hash Algorithm 2 (224 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
+Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
@@ -4467,16 +4667,66 @@ pe-section is a MISP object available in JSON format at
text
text
md5
md5
Free text value to attach to the section
+[Insecure] MD5 hash (128 bits)
++
size-in-bytes
size-in-bytes
Size of the section, in bytes
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
characteristic
text
sha256
sha256
sha224
sha224
Secure Hash Algorithm 2 (256 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
+Secure Hash Algorithm 2 (224 bits)
@@ -4555,46 +4795,6 @@ person is a MISP object available in JSON format at
place-of-birth
place-of-birth
Place of birth of a natural person.
--
gender
gender
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
--
alias
text
Alias name or known as.
--
passport-number
passport-number
The passport number of a natural person.
--
last-name
last-name
nationality
nationality
text
text
The nationality of a natural person.
+A description of the person or identity.
text
text
place-of-birth
place-of-birth
A description of the person or identity.
+Place of birth of a natural person.
@@ -4635,6 +4835,26 @@ person is a MISP object available in JSON format at
social-security-number
text
Social security number
++
alias
text
Alias name or known as.
++
title
text
redress-number
redress-number
gender
gender
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
--
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
--
first-name
first-name
First name of a natural person.
+The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
social-security-number
text
middle-name
middle-name
Social security number
+Middle name of a natural person.
++
passport-number
passport-number
The passport number of a natural person.
@@ -4695,6 +4905,36 @@ person is a MISP object available in JSON format at
nationality
nationality
The nationality of a natural person.
++
first-name
first-name
First name of a natural person.
++
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
++
passport-country
passport-country
middle-name
middle-name
redress-number
redress-number
Middle name of a natural person.
+The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
@@ -4753,13 +4993,13 @@ phone is a MISP object available in JSON format at
serial-number
text
text
Serial Number.
+A description of the phone.
+
imsi
+text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
++
first-seen
datetime
When the phone has been accessible or seen for the first time.
++
gummei
text
guti
serial-number
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
+Serial Number.
text
text
A description of the phone.
--
msisdn
text
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
++
tmsi
text
imsi
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
--
first-seen
datetime
When the phone has been accessible or seen for the first time.
--
callback-average
-counter
Average size of a callback
--
memory-allocations
counter
Amount of memory allocations
--
local-references
counter
callback-largest
callbacks
counter
Largest callback
--
text
text
Description of the r2graphity object
--
create-thread
counter
Amount of calls to CreateThread
--
get-proc-address
counter
Amount of calls to GetProcAddress
+Amount of callbacks (functions started as thread)
@@ -4971,6 +5161,36 @@ r2graphity is a MISP object available in JSON format at
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
++
memory-allocations
counter
Amount of memory allocations
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
shortest-path-to-create-thread
counter
create-thread
counter
Amount of calls to CreateThread
++
referenced-strings
counter
Amount of referenced strings
++
total-functions
counter
ratio-api
float
text
text
Ratio: amount of API calls per kilobyte of code section
+Description of the r2graphity object
unknown-references
gml
attachment
Graph export in G>raph Modelling Language format
++
callback-average
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
+Average size of a callback
++
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
@@ -5031,30 +5291,10 @@ r2graphity is a MISP object available in JSON format at
refsglobalvar
unknown-references
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
referenced-strings
counter
Amount of referenced strings
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
+Amount of API calls not ending in a function (Radare2 bug, probalby)
@@ -5071,10 +5311,20 @@ r2graphity is a MISP object available in JSON format at
gml
attachment
ratio-string
float
Graph export in G>raph Modelling Language format
+Ratio: amount of referenced strings per kilobyte of code section
++
callback-largest
counter
Largest callback
@@ -5091,20 +5341,10 @@ r2graphity is a MISP object available in JSON format at
callbacks
get-proc-address
counter
Amount of callbacks (functions started as thread)
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
+Amount of calls to GetProcAddress
@@ -5149,13 +5389,13 @@ regexp is a MISP object available in JSON format at
regexp-type
type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
+Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
+
regexp-type
+text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
++
comment
comment
type
text
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
--
name
-text
Name of the registry key
--
data-type
text
name
text
Name of the registry key
++
last-modified
datetime
data
text
Data stored in the registry key
--
key
regkey
Full key path
--
root-keys
text
data
text
Data stored in the registry key
++
key
regkey
Full key path
++
summary
+case-number
text
Free text summary of the report
+Case number
case-number
summary
text
Case number
+Free text summary of the report
@@ -5393,20 +5633,10 @@ rtir is a MISP object available in JSON format at
ticket-number
constituency
text
ticket-number of the RTIR ticket
--
queue
text
Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
+Constituency of the RTIR ticket
@@ -5423,10 +5653,20 @@ rtir is a MISP object available in JSON format at
constituency
queue
text
Constituency of the RTIR ticket
+Queue of the RTIR ticket ['incident', 'investigations', 'blocks', 'incident reports']
++
ticket-number
text
ticket-number of the RTIR ticket
@@ -5443,20 +5683,20 @@ rtir is a MISP object available in JSON format at
status
classification
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
+Classification of the RTIR ticket
classification
status
text
Classification of the RTIR ticket
+Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
@@ -5501,26 +5741,6 @@ sandbox-report is a MISP object available in JSON format at
sandbox-type
text
The type of sandbox used ['on-premise', 'web', 'saas']
--
permalink
link
Permalink reference
--
score
text
saas-sandbox
sandbox-type
text
A non-on-premise sandbox, also results are not publicly available ['forticloud-sandbox', 'joe-sandbox-cloud', 'symantec-cas-cloud']
+The type of sandbox used ['on-premise', 'web', 'saas']
permalink
link
Permalink reference
++
saas-sandbox
text
A non-on-premise sandbox, also results are not publicly available ['forticloud-sandbox', 'joe-sandbox-cloud', 'symantec-cas-cloud']
++
Sandbox detection signature.
++ + | ++sb-signature is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +
---|---|---|---|
text |
+text |
+
+ Additional signature description + |
+
+ + |
+
datetime |
+datetime |
+
+ Datetime + |
+
+ + |
+
signature |
+text |
+
+ Name of detection signature - set the description of the detection signature as a comment + |
+
+ + |
+
software |
+text |
+
+ Name of Sandbox software + |
+
+ + |
+
SccpCdGT
+MapVersion
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
--
Category
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
+Map version. ['1', '2', '3']
MapMscGT
MapGsmscfGT
text
MAP MSC GT. Phone number.
+MAP GSMSCF GT. Phone number.
SccpCgPC
SccpCdSSN
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
--
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
--
MapApplicationContext
text
MAP application context in OID format.
--
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
--
MapMsisdn
text
MAP MSISDN. Phone number.
--
text
text
A description of the attack seen via SS7 logging.
+Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
@@ -5719,120 +5977,10 @@ ss7-attack is a MISP object available in JSON format at
SccpCdSSN
MapApplicationContext
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
MapUssdContent
text
MAP USSD Content.
--
MapVersion
text
Map version. ['1', '2', '3']
--
MapSmsTP-DCS
text
MAP SMS TP-DCS.
--
MapUssdCoding
text
MAP USSD Content.
--
MapGmlc
text
MAP GMLC. Phone number.
--
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
MapSmsTP-PID
text
MAP SMS TP-PID.
--
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
--
MapSmscGT
text
MAP SMSC. Phone number.
--
MapSmsTypeNumber
text
MAP SMS TypeNumber.
--
first-seen
datetime
When the attack has been seen for the first time.
+MAP application context in OID format.
@@ -5849,6 +5997,146 @@ ss7-attack is a MISP object available in JSON format at
MapUssdContent
text
MAP USSD Content.
++
MapSmsText
text
MAP SMS Text. Important indicators in SMS text.
++
MapSmsTypeNumber
text
MAP SMS TypeNumber.
++
MapSmsTP-DCS
text
MAP SMS TP-DCS.
++
MapMscGT
text
MAP MSC GT. Phone number.
++
MapMsisdn
text
MAP MSISDN. Phone number.
++
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
++
text
text
A description of the attack seen via SS7 logging.
++
MapSmsTP-OA
text
MAP SMS TP-OA. Phone number.
++
MapSmscGT
text
MAP SMSC. Phone number.
++
MapUssdCoding
text
MAP USSD Content.
++
first-seen
datetime
When the attack has been seen for the first time.
++
SccpCgGT
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
++
SccpCdGT
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
++
MapImsi
text
MapGsmscfGT
MapGmlc
text
MAP GSMSCF GT. Phone number.
+MAP GMLC. Phone number.
Category
text
Category ['Cat0', 'Cat1', 'Cat2.1', 'Cat2.2', 'Cat3.1', 'Cat3.2', 'Cat3.3', 'CatSMS', 'CatSpoofing']
++
MapSmsTP-PID
text
MAP SMS TP-PID.
++
SccpCdPC
text
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
++
comment
-comment
stix2-pattern
stix2-pattern
A description of the stix2-pattern.
+STIX 2 pattern
stix2-pattern
stix2-pattern
comment
comment
STIX 2 pattern
+A description of the stix2-pattern.
@@ -5975,6 +6293,46 @@ tor-node is a MISP object available in JSON format at
text
text
Tor node comment.
++
published
datetime
router’s publication time. This can be different from first-seen and last-seen.
++
flags
text
list of flag associated with the node.
++
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
++
description
text
address
ip-src
IP address of the Tor node seen.
--
flags
text
list of flag associated with the node.
--
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
--
fingerprint
text
text
text
Tor node comment.
--
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
document
text
published
first-seen
datetime
router’s publication time. This can be different from first-seen and last-seen.
+When the Tor node designed by the IP address has been seen for the first time.
address
ip-src
IP address of the Tor node seen.
++
last-seen
datetime
text
text
Description of the URL
++
tld
text
Top-Level Domain
++
last-seen
datetime
Last time this URL has been seen
++
port
port
Port number
++
domain_without_tld
text
Domain without Top-Level Domain
++
first-seen
datetime
First time this URL has been seen
++
query_string
text
host
hostname
Full hostname
--
url
url
Full URL
--
port
port
Port number
--
credential
scheme
text
Credential (username, password)
--
text
text
Description of the URL
--
first-seen
datetime
First time this URL has been seen
+Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
@@ -6223,36 +6551,6 @@ url is a MISP object available in JSON format at
domain
domain
Full domain
--
scheme
text
Scheme ['http', 'https', 'ftp', 'gopher', 'sip']
--
tld
text
Top-Level Domain
--
fragment
text
last-seen
datetime
credential
text
Last time this URL has been seen
+Credential (username, password)
+
domain_without_tld
text
url
url
Domain without Top-Level Domain
+Full URL
++
domain
domain
Full domain
++
host
hostname
Full hostname
@@ -6321,6 +6639,36 @@ victim is a MISP object available in JSON format at
external
target-external
External target organisations affected by this attack.
++
node
target-machine
Name(s) of node that was targeted.
++
sectors
text
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
++
name
target-org
ip-address
ip-dst
IP address(es) of the node targeted.
++
roles
text
The list of roles targeted within the victim.
++
description
text
sectors
text
user
target-user
The list of sectors that the victim belong to ['agriculture', 'aerospace', 'automotive', 'communications', 'construction', 'defence', 'education', 'energy', 'engineering', 'entertainment', 'financial services', 'government national', 'government regional', 'government local', 'government public services', 'healthcare', 'hospitality leisure', 'infrastructure', 'insurance', 'manufacturing', 'mining', 'non profit', 'pharmaceuticals', 'retail', 'technology', 'telecommunications', 'transportation', 'utilities']
--
ip-address
ip-dst
IP address(es) of the node targeted.
--
node
target-machine
Name(s) of node that was targeted.
+The username(s) of the user targeted.
@@ -6391,16 +6739,6 @@ victim is a MISP object available in JSON format at
external
target-external
External target organisations affected by this attack.
--
target-email
user
target-user
The username(s) of the user targeted.
--
roles
text
The list of roles targeted within the victim.
--
first-submission
+community-score
text
Community Score
++
last-submission
datetime
First Submission
+Last Submission
@@ -6489,20 +6817,10 @@ virustotal-report is a MISP object available in JSON format at
community-score
text
Community Score
--
last-submission
first-submission
datetime
Last Submission
+First Submission
@@ -6567,23 +6885,13 @@ vulnerability is a MISP object available in JSON format at
vulnerable_configuration
text
published
datetime
The vulnerable configuration is described in CPE format
+Initial publication date
-
summary
text
Summary of the vulnerability
-+
published
-datetime
state
text
Initial publication date
--
created
datetime
First time when the vulnerability was discovered
+State of the vulnerability. A vulnerability can have multiple states depending of the current actions performed. ['Published', 'Embargo', 'Reviewed', 'Vulnerability ID Assigned', 'Reported', 'Fixed']
@@ -6627,6 +6925,36 @@ vulnerability is a MISP object available in JSON format at
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
++
created
datetime
First time when the vulnerability was discovered
++
summary
text
Summary of the vulnerability
++
references
link
state
text
State of the vulnerability. A vulnerability can have multiple states depending of the current actions performed. ['Published', 'Embargo', 'Reviewed', 'Vulnerability ID Assigned', 'Reported', 'Fixed']
--
registrant-org
+whois-registrant-org
Registrant organisation
++
text
text
creation-date
datetime
registrar
whois-registrar
Initial creation of the whois entry
--
registrant-org
whois-registrant-org
Registrant organisation
+Registrar of the whois entry
@@ -6725,6 +7043,26 @@ whois is a MISP object available in JSON format at
registrant-name
whois-registrant-name
Registrant name
++
nameserver
hostname
Nameserver
++
modification-date
datetime
registrant-name
whois-registrant-name
registrant-email
whois-registrant-email
Registrant name
+Registrant email address
@@ -6755,26 +7093,6 @@ whois is a MISP object available in JSON format at
registrant-email
whois-registrant-email
Registrant email address
--
registrar
whois-registrar
Registrar of the whois entry
--
registrant-phone
whois-registrant-phone
nameserver
hostname
creation-date
datetime
Nameserver
+Initial creation of the whois entry
@@ -6833,26 +7151,6 @@ x509 is a MISP object available in JSON format at
pubkey-info-modulus
text
Modulus of the public key
--
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
text
text
version
text
Version of the certificate
--
serial-number
text
Serial number of the certificate
--
pubkey-info-size
text
Length of the public key (in bits)
--
pubkey-info-exponent
text
Exponent of the public key
--
issuer
text
Issuer of the certificate
--
pubkey-info-algorithm
text
x509-fingerprint-sha256
x509-fingerprint-sha256
validity-not-before
datetime
Secure Hash Algorithm 2 (256 bits)
+Certificate invalid before that date
subject
pubkey-info-size
text
Subject of the certificate
+Length of the public key (in bits)
@@ -6953,20 +7201,10 @@ x509 is a MISP object available in JSON format at
raw-base64
text
x509-fingerprint-sha1
x509-fingerprint-sha1
Raw certificate base64 encoded
--
validity-not-before
datetime
Certificate invalid before that date
+[Insecure] Secure Hash Algorithm 1 (160 bits)
pubkey-info-modulus
text
Modulus of the public key
++
pubkey-info-exponent
text
Exponent of the public key
++
serial-number
text
Serial number of the certificate
++
subject
text
Subject of the certificate
++
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
++
raw-base64
text
Raw certificate base64 encoded
++
issuer
text
Issuer of the certificate
++
version
text
Version of the certificate
++
yara
+yara-hunt
yara
Yara rule generated from -y.
+Wide yara rule generated from -yh.
@@ -7041,6 +7359,16 @@ yabin is a MISP object available in JSON format at
whitelist
comment
Whitelist name used to generate the rules.
++
comment
comment
yara-hunt
yara
yara
Wide yara rule generated from -yh.
+Yara rule generated from -y.
whitelist
comment
Whitelist name used to generate the rules.
--