From b544e86791f385b1c08d64cd3a265e1647ea24ff Mon Sep 17 00:00:00 2001
From: Alexandre Dulaunoy
Date: Sun, 17 Sep 2017 13:57:56 +0200
Subject: [PATCH] Objects updated including values_list
---
objects.html | 3556 +-
objects.pdf | 101091 ++++++++++++++++++++++--------------------------
2 files changed, 48263 insertions(+), 56384 deletions(-)
diff --git a/objects.html b/objects.html
index 2af6c0f..faaf213 100755
--- a/objects.html
+++ b/objects.html
@@ -518,27 +518,37 @@ ail-leak is a MISP object available in JSON format at origin
url
The link where the leak is (or was) accessible at first-seen.
+
original-date
last-seen
datetime
When the information available in the leak was created. It’s usually before the first-seen.
+
last-seen
text
text
+
+
original-date
datetime
When the leak has been accessible or seen for the last time.
+
@@ -548,27 +558,17 @@ ail-leak is a MISP object available in JSON format at
type
text
Type of information leak as discovered and classified by an AIL module.
+
text
text
A description of the leak which could include the potential victim(s) or description of the leak.
--
sensor
text
The AIL sensor uuid where the leak was processed and analysed.
+
@@ -578,7 +578,7 @@ ail-leak is a MISP object available in JSON format at
first-seen
datetime
When the leak has been accessible or seen for the first time.
+
@@ -623,40 +623,30 @@ cookie is a MISP object available in JSON format at
type
text
Type of cookie and how it’s used in this specific object.
-text
text
text
A description of the cookie.
-
cookie-name
text
cookie
cookie
Name of the cookie (if splitted)
+
cookie
cookie
cookie-name
text
Full cookie
+
@@ -666,7 +656,17 @@ cookie is a MISP object available in JSON format at
cookie-value
text
Value of the cookie (if splitted)
++
+
type
text
@@ -711,61 +711,11 @@ credit-card is a MISP object available in JSON format at
card-security-code
text
Card security code as embossed or printed on the card.
--
issued
datetime
Initial date of validity or issued date.
--
cc-number
cc-number
credit-card number as encoded on the card.
--
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
--
comment
comment
A description of the card.
-
name
text
Name of the card owner.
-
expiration
datetime
Maximum date of validity
++
+
name
text
+
+
issued
datetime
+
+
cc-number
cc-number
+
+
version
comment
+
+
card-security-code
text
@@ -819,21 +819,11 @@ ddos is a MISP object available in JSON format at
ip-src
ip-src
IP address originating the attack
-text
text
dst-port
port
Destination port of the attack
-
ip-dst
ip-dst
Destination ID (victim)
-
total-pps
counter
Packets per second
--
total-bps
counter
Bits per second
--
last-seen
datetime
End of the attack
-
src-port
port
Port originating the attack
-
text
text
Description of the DDoS
-
protocol
text
Protocol used for the attack
+Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
++
ip-src
ip-src
+
+
total-pps
counter
+
+
total-bps
counter
+
+
last-seen
datetime
+
+
dst-port
port
@@ -912,7 +912,7 @@ ddos is a MISP object available in JSON format at
first-seen
datetime
Beginning of the attack
+
@@ -960,7 +960,7 @@ domain|ip is a MISP object available in JSON format at
domain
domain
Domain name
+
@@ -970,7 +970,7 @@ domain|ip is a MISP object available in JSON format at
text
text
A description of the tuple
+
@@ -980,18 +980,8 @@ domain|ip is a MISP object available in JSON format at
last-seen
datetime
Last time the tuple has been seen
-
ip
ip-dst
IP Address
-
first-seen
datetime
First time the tuple has been seen
++
+
ip
ip-dst
@@ -1045,51 +1045,11 @@ elf is a MISP object available in JSON format at
entrypoint-address
text
Address of the entry point
--
type
text
Type of ELF
-
arch
text
Architecture of the ELF file
--
text
text
Free text value to attach to the ELF
--
number-sections
counter
Number of sections
-
os_abi
text
Header operating system application binary interface (ABI)
++
+
entrypoint-address
text
+
+
number-sections
counter
+
+
arch
text
+
+
type
text
@@ -1143,61 +1143,11 @@ elf-section is a MISP object available in JSON format at
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
-entropy
float
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
text
text
Free text value to attach to the section
-
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
+
name
text
sha384
sha384
Name of the section
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
+
flag
text
sha512/256
sha512/256
Flag of the section
--
md5
md5
[Insecure] MD5 hash (128 bits)
+
@@ -1256,37 +1186,107 @@ elf-section is a MISP object available in JSON format at
type
text
Type of the section
+
sha1
sha1
ssdeep
ssdeep
[Insecure] Secure Hash Algorithm 1 (160 bits)
+
ssdeep
ssdeep
sha256
sha256
Fuzzy hash using context triggered piecewise hashes (CTPH)
+
entropy
float
flag
text
Entropy of the whole section
++
+
md5
md5
+
+
name
text
+
+
sha224
sha224
+
+
sha512
sha512
+
+
sha1
sha1
+
+
text
text
+
+
size-in-bytes
size-in-bytes
@@ -1331,91 +1331,11 @@ email is a MISP object available in JSON format at
mime-boundary
email-mime-boundary
MIME Boundary
--
thread-index
email-thread-index
Identifies a particular conversation thread
-
header
email-header
Full headers
--
to
email-dst
Destination email address
--
from-display-name
email-src-display-name
Display name of the sender
--
from
email-src
Sender email address
--
attachment
email-attachment
Attachment
--
message-id
email-message-id
Message ID
--
reply-to
email-reply-to
Email address the reply will be sent to
-
subject
email-subject
Subject
++
+
reply-to
email-reply-to
+
+
attachment
email-attachment
+
+
mime-boundary
email-mime-boundary
+
+
from
email-src
+
+
from-display-name
email-src-display-name
+
+
message-id
email-message-id
+
+
to-display-name
email-dst-display-name
+
+
to
email-dst
@@ -1434,17 +1434,17 @@ email is a MISP object available in JSON format at
send-date
datetime
Date the email has been sent
+
to-display-name
email-dst-display-name
header
email-header
Display name of the receiver
+
@@ -1454,7 +1454,7 @@ email is a MISP object available in JSON format at
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
+
@@ -1499,71 +1499,21 @@ file is a MISP object available in JSON format at
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
-entropy
float
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
text
text
Free text value to attach to the file
-
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
-authentihash
authentihash
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
-
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
+
filename
filename
+
+
tlsh
tlsh
+
+
sha384
sha384
+
+
sha512/256
sha512/256
+
+
ssdeep
ssdeep
+
+
sha256
sha256
+
+
pattern-in-file
pattern-in-file
+
+
md5
md5
+
+
malware-sample
malware-sample
+
+
sha224
sha224
+
+
sha512
sha512
+
+
sha1
sha1
@@ -1582,7 +1652,17 @@ file is a MISP object available in JSON format at
mimetype
text
Mime type
++
+
text
text
@@ -1592,92 +1672,12 @@ file is a MISP object available in JSON format at
size-in-bytes
size-in-bytes
Size of the file, in bytes
+
authentihash
authentihash
Authenticode executable signature hash
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
filename
filename
Filename on disk
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
--
entropy
float
Entropy of the whole file
--
malware-sample
malware-sample
The file itself (binary)
--
region
text
Region.
++
+
country
text
@@ -1730,17 +1740,37 @@ geolocation is a MISP object available in JSON format at
city
text
City.
+
longitude
altitude
float
The longitude is the decimal value of the longitude in the World Geodetic System 84 (WGS84) reference
++
+
latitude
float
+
+
text
text
@@ -1750,57 +1780,27 @@ geolocation is a MISP object available in JSON format at
last-seen
datetime
When the location was seen for the last time.
--
country
text
Country.
-
text
text
A generic description of the location.
-
latitude
float
The latitude is the decimal value of the latitude in the World Geodetic System 84 (WGS84) reference.
--
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
--
first-seen
datetime
When the location was seen for the first time.
++
+
longitude
float
@@ -1845,10 +1845,40 @@ http-request is a MISP object available in JSON format at
basicauth-password
user-agent
user-agent
+
+
cookie
text
HTTP Basic Authentication Password
++
+
proxy-user
text
+
+
url
url
@@ -1858,68 +1888,18 @@ http-request is a MISP object available in JSON format at
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
+
cookie
proxy-password
text
An HTTP cookie previously sent by the server with Set-Cookie
-
text
text
HTTP Request comment
--
proxy-user
text
HTTP Proxy Username
--
uri
uri
Request URI
--
user-agent
user-agent
The user agent string of the user agent
--
basicauth-user
text
HTTP Basic Authentication Username
-
host
hostname
The domain name of the server
+
basicauth-user
text
+
+
uri
uri
+
+
basicauth-password
text
+
+
text
text
+
+
content-type
other
The MIME type of the body of the request
-
proxy-password
text
HTTP Proxy Password
-
referer
referer
This is the address of the previous web page from which a link to the currently requested page was followed
-
url
url
Full HTTP Request URL
-
dst-port
-port
Destination port
--
src-port
port
Source port
+
@@ -2036,7 +2026,17 @@ ip|port is a MISP object available in JSON format at
ip
ip-dst
IP Address
++
+
dst-port
port
@@ -2046,7 +2046,7 @@ ip|port is a MISP object available in JSON format at
last-seen
datetime
Last time the tuple has been seen
+
@@ -2056,7 +2056,7 @@ ip|port is a MISP object available in JSON format at
text
text
Description of the tuple
+
@@ -2066,7 +2066,7 @@ ip|port is a MISP object available in JSON format at
first-seen
datetime
First time the tuple has been seen
+
@@ -2111,30 +2111,20 @@ macho is a MISP object available in JSON format at
name
text
+
+
entrypoint-address
text
Address of the entry point
--
text
text
Free text value to attach to the Mach-O file
--
number-sections
counter
Number of sections
+
@@ -2144,21 +2134,31 @@ macho is a MISP object available in JSON format at
type
text
Type of Mach-O
+
name
text
text
Binary’s name
+
+
number-sections
counter
+
sha384
-sha384
Secure Hash Algorithm 2 (384 bits)
-entropy
float
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
text
text
Free text value to attach to the section
-
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
+
sha384
sha384
+
+
sha512/256
sha512/256
+
+
ssdeep
ssdeep
+
+
sha256
sha256
+
+
md5
md5
@@ -2272,27 +2272,27 @@ macho-section is a MISP object available in JSON format at
name
text
Name of the section
+
sha512/256
sha512/256
sha224
sha224
Secure Hash Algorithm 2 (256 bits)
+
md5
md5
sha512
sha512
[Insecure] MD5 hash (128 bits)
+
@@ -2302,27 +2302,27 @@ macho-section is a MISP object available in JSON format at
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
+
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
-text
text
+
entropy
float
size-in-bytes
size-in-bytes
Entropy of the whole section
+
@@ -2367,31 +2367,11 @@ passive-dns is a MISP object available in JSON format at
origin
text
Origin of the Passive DNS response
--
zone_time_last
time_first
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
-
zone_time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
-
sensor_id
text
Sensor information where the record was seen
+
count
counter
rrname
text
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
+
rrtype
text
text
+
+
zone_time_first
datetime
rdata
text
Resource records of the queried resource
++
+
origin
text
@@ -2440,27 +2440,37 @@ passive-dns is a MISP object available in JSON format at
bailiwick
text
Best estimate of the apex of the zone where this data is authoritative
+
rrtype
text
text
Resource Record type as seen by the passive DNS
+
time_first
count
counter
+
+
zone_time_last
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
+
@@ -2470,18 +2480,8 @@ passive-dns is a MISP object available in JSON format at
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
-
rrname
text
Resource Record name of the queried resource
-
compilation-timestamp
-datetime
Compilation timestamp defined in the PE header
--
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
--
legal-copyright
text
LegalCopyright in the resources
--
company-name
text
CompanyName in the resources
--
imphash
imphash
Hash (md5) calculated from the import table
-
text
text
Free text value to attach to the PE
--
number-sections
counter
Number of sections
--
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
--
original-filename
filename
OriginalFilename in the resources
--
entrypoint-address
text
Address of the entry point
--
lang-id
text
Lang ID in the resources
--
type
text
Type of PE
--
file-version
text
FileVersion in the resources
--
product-name
text
ProductName in the resources
--
product-version
text
ProductVersion in the resources
--
file-description
text
FileDescription in the resources
-
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
++
+
compilation-timestamp
datetime
+
+
impfuzzy
impfuzzy
+
+
file-description
text
+
+
product-name
text
+
+
original-filename
filename
+
+
type
text
+
+
pehash
pehash
+
+
file-version
text
+
+
legal-copyright
text
+
+
entrypoint-address
text
+
+
lang-id
text
+
+
text
text
@@ -2698,12 +2668,42 @@ pe is a MISP object available in JSON format at
internal-filename
filename
InternalFilename in the resources
+
number-sections
counter
+
+
imphash
imphash
+
+
product-version
text
+
+
sha384
-sha384
Secure Hash Algorithm 2 (384 bits)
-entropy
float
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
size-in-bytes
size-in-bytes
Size of the section, in bytes
--
text
text
Free text value to attach to the section
-
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
-
name
text
Name of the section
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
-
characteristic
text
Characteristic of the section
+
entropy
float
sha384
sha384
Entropy of the whole section
++
+
sha512/256
sha512/256
+
+
ssdeep
ssdeep
+
+
sha256
sha256
+
+
md5
md5
+
+
name
text
+
+
sha224
sha224
+
+
sha512
sha512
+
+
sha1
sha1
+
+
text
text
+
+
size-in-bytes
size-in-bytes
@@ -2921,71 +2921,11 @@ person is a MISP object available in JSON format at
middle-name
middle-name
Middle name of a natural person
-passport-country
passport-country
gender
gender
The gender of a natural person.
--
first-name
first-name
First name of a natural person.
--
passport-expiration
passport-expiration
The expiration date of a passport.
--
place-of-birth
place-of-birth
Place of birth of a natural person.
--
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
--
passport-number
passport-number
The passport number of a natural person.
-
nationality
nationality
The nationality of a natural person.
-
passport-country
passport-country
The country in which the passport was issued.
--
redress-number
redress-number
The Redress Control Number is the record identifier for people who apply for redress through the DHS Travel Redress Inquiry Program (DHS TRIP). DHS TRIP is for travelers who have been repeatedly identified for additional screening and who want to file an inquiry to have erroneous information corrected in DHS systems.
-
last-name
last-name
Last name of a natural person.
++
+
first-name
first-name
+
+
redress-number
redress-number
+
+
date-of-birth
date-of-birth
+
+
gender
gender
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
++
middle-name
middle-name
+
+
place-of-birth
place-of-birth
@@ -3034,12 +3014,32 @@ person is a MISP object available in JSON format at
text
text
A description of the person or identity.
+
passport-expiration
passport-expiration
+
+
passport-number
passport-number
+
+
serial-number
+imsi
text
Serial Number.
-
text
text
A description of the phone.
--
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
-
msisdn
text
MSISDN (pronounced as /'em es ai es di en/ or misden) is a number uniquely identifying a subscription in a GSM or a UMTS mobile network. Simply put, it is the mapping of the telephone number to the SIM card in a mobile/cellular phone. This abbreviation has a several interpretations, the most common one being Mobile Station International Subscriber Directory Number.
-
first-seen
datetime
When the phone has been accessible or seen for the first time.
--
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
--
imsi
text
A usually unique International Mobile Subscriber Identity (IMSI) is allocated to each mobile subscriber in the GSM/UMTS/EPS system. IMSI can also refer to International Mobile Station Identity in the ITU nomenclature.
-
imei
text
International Mobile Equipment Identity (IMEI) is a number, usually unique, to identify 3GPP and iDEN mobile phones, as well as some satellite phones.
++
+
tmsi
text
@@ -3162,7 +3122,27 @@ phone is a MISP object available in JSON format at
gummei
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
++
+
text
text
+
+
serial-number
text
@@ -3172,12 +3152,32 @@ phone is a MISP object available in JSON format at
last-seen
datetime
When the phone has been accessible or seen for the last time.
+
first-seen
datetime
+
+
guti
text
+
+
callback-average
counter
Average size of a callback
--
local-references
counter
Amount of API calls inside a code section
--
total-api
counter
Total amount of API calls
--
text
text
Description of the r2graphity object
--
gml
attachment
Graph export in G>raph Modelling Language format
--
total-functions
counter
Total amount of functions in the file.
--
miss-api
counter
Amount of API call reference that does not resolve to a function offset
--
referenced-strings
counter
Amount of referenced strings
--
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
--
ratio-string
float
Ratio: amount of referenced strings per kilobyte of code section
--
callback-largest
counter
Largest callback
--
create-thread
counter
Amount of calls to CreateThread
--
ratio-functions
float
Ratio: amount of functions per kilobyte of code section
--
not-referenced-strings
counter
Amount of not referenced strings
--
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
--
r2-commit-version
text
Radare2 commit ID used to generate this object
--
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
--
get-proc-address
counter
Amount of calls to GetProcAddress
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
--
callbacks
counter
Amount of callbacks (functions started as thread)
+
@@ -3430,7 +3230,207 @@ r2graphity is a MISP object available in JSON format at
memory-allocations
counter
Amount of memory allocations
++
+
get-proc-address
counter
+
+
r2-commit-version
text
+
+
total-api
counter
+
+
refsglobalvar
counter
+
+
referenced-strings
counter
+
+
miss-api
counter
+
+
ratio-string
float
+
+
text
text
+
+
callbacks
counter
+
+
ratio-api
float
+
+
unknown-references
counter
+
+
local-references
counter
+
+
not-referenced-strings
counter
+
+
callback-largest
counter
+
+
gml
attachment
+
+
total-functions
counter
+
+
shortest-path-to-create-thread
counter
+
+
ratio-functions
float
+
+
dangling-strings
counter
+
+
create-thread
counter
@@ -3475,20 +3475,20 @@ regexp is a MISP object available in JSON format at
regexp
text
comment
comment
regexp
+
comment
comment
regexp
text
A description of the regular expression.
+
@@ -3498,7 +3498,7 @@ regexp is a MISP object available in JSON format at
regexp-type
text
Type of the regular expression syntax.
+Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
@@ -3543,31 +3543,11 @@ registry-key is a MISP object available in JSON format at
data-type
reg-datatype
Registry value type
-data
reg-data
hive
reg-hive
Hive used to store the registry key (file on disk)
--
key
reg-key
Full key path
-
last-modified
datetime
Last time the registry key has been modified
++
+
hive
reg-hive
@@ -3586,17 +3576,27 @@ registry-key is a MISP object available in JSON format at
name
reg-name
Name of the registry key
+
data
reg-data
key
reg-key
Data stored in the registry key
++
+
data-type
reg-datatype
@@ -3641,90 +3641,10 @@ tor-node is a MISP object available in JSON format at
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
--
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
published
datetime
router’s publication time. This can be different from first-seen and last-seen.
--
version_line
text
versioning information reported by the node.
--
text
text
Tor node comment.
--
address
ip-src
IP address of the Tor node seen.
--
document
text
Raw document from the consensus.
--
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
--
description
text
Tor node description.
+
@@ -3734,17 +3654,57 @@ tor-node is a MISP object available in JSON format at
flags
text
list of flag associated with the node.
+
nickname
version
text
router’s nickname.
++
+
document
text
+
+
first-seen
datetime
+
+
address
ip-src
+
+
version_line
text
@@ -3754,12 +3714,52 @@ tor-node is a MISP object available in JSON format at
fingerprint
text
router’s fingerprint.
+
text
text
+
+
nickname
text
+
+
last-seen
datetime
+
+
published
datetime
+
+
host
-hostname
Full hostname
--
domain
domain
Full domain
-
last-seen
datetime
Last time this URL has been seen
--
text
text
Description of the URL
--
subdomain
text
Subdomain
--
fragment
text
Fragment identifier is a short string of characters that refers to a resource that is subordinate to another, primary resource.
-
url
url
Full URL
+
credential
text
port
port
Credential (username, password)
+
@@ -3882,7 +3832,7 @@ url is a MISP object available in JSON format at
tld
text
Top-Level Domain
+
@@ -3892,7 +3842,17 @@ url is a MISP object available in JSON format at
first-seen
datetime
First time this URL has been seen
++
+
host
hostname
@@ -3902,28 +3862,8 @@ url is a MISP object available in JSON format at
scheme
text
Scheme
-
query_string
text
Query (after path, preceded by '?')
--
port
port
Port number
-
resource_path
text
Path (between hostname:port and query)
++
+
credential
text
@@ -3942,7 +3892,57 @@ url is a MISP object available in JSON format at
domain_without_tld
text
Domain without Top-Level Domain
++
+
subdomain
text
+
+
fragment
text
+
+
text
text
+
+
last-seen
datetime
+
+
query_string
text
@@ -3990,58 +3990,8 @@ vulnerability is a MISP object available in JSON format at
modified
datetime
Last modification date
-
published
datetime
Initial publication date
--
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
--
summary
text
Summary of the vulnerability
--
text
text
Description of the vulnerability
--
references
link
External references
-
id
vulnerability
Vulnerability ID (generally CVE, but not necessarely)
++
+
references
link
+
+
vulnerable_configuration
text
+
+
summary
text
+
+
text
text
+
+
published
datetime
@@ -4095,21 +4095,11 @@ whois is a MISP object available in JSON format at
registar
whois-registar
Registar of the whois entry
-expiration-date
datetime
text
text
Full whois entry
-
modification-date
datetime
Last update of the whois entry
+
@@ -4128,7 +4118,7 @@ whois is a MISP object available in JSON format at
registrant-name
whois-registrant-name
Registrant name
+
@@ -4138,28 +4128,8 @@ whois is a MISP object available in JSON format at
registrant-phone
whois-registrant-phone
Registrant phone number
-
expiration-date
datetime
Expiration of the whois entry
--
registrant-email
whois-registrant-email
Registrant email address
-
creation-date
datetime
Initial creation of the whois entry
++
+
text
text
+
+
registrant-email
whois-registrant-email
+
+
registar
whois-registar
@@ -4178,7 +4178,7 @@ whois is a MISP object available in JSON format at
domain
domain
Domain of the whois entry
+
@@ -4223,111 +4223,11 @@ x509 is a MISP object available in JSON format at
serial-number
text
Serial number of the certificate
--
issuer
text
Issuer of the certificate
-
validity-not-after
datetime
Certificate invalid after that date
--
validity-not-before
datetime
Certificate invalid before that date
--
version
text
Version of the certificate
--
x509-fingerprint-sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
text
text
Free text description of hte certificate
--
pubkey-info-modulus
text
Modulus of the public key
--
pubkey-info-size
text
Length of the public key (in bits)
--
x509-fingerprint-sha1
sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
--
raw-base64
text
Raw certificate base64 encoded
-
x509-fingerprint-md5
md5
[Insecure] MD5 hash (128 bits)
++
+
raw-base64
text
@@ -4346,7 +4256,27 @@ x509 is a MISP object available in JSON format at
subject
text
Subject of the certificate
++
+
x509-fingerprint-sha1
sha1
+
+
x509-fingerprint-sha256
sha256
@@ -4356,7 +4286,47 @@ x509 is a MISP object available in JSON format at
pubkey-info-exponent
text
Exponent of the public key
++
+
validity-not-before
datetime
+
+
version
text
+
+
pubkey-info-modulus
text
+
+
pubkey-info-size
text
@@ -4366,7 +4336,37 @@ x509 is a MISP object available in JSON format at
pubkey-info-algorithm
text
Algorithm of the public key
++
+
text
text
+
+
serial-number
text
+
+
validity-not-after
datetime
@@ -4411,30 +4411,30 @@ yabin is a MISP object available in JSON format at
whitelist
comment
comment
Whitelist name used to generate the rules.
+
yara
yara
version
comment
Yara rule generated from -y.
+
+
comment
whitelist
comment
A description of Yara rule generated.
+
@@ -4444,21 +4444,21 @@ yabin is a MISP object available in JSON format at
yara-hunt
yara
Wide yara rule generated from -yh.
+
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
-yara
yara
+